Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To target an Intune app, policy, or profile by OS version, create an assignment filter for managed devices or managed apps, build a rule with operatingSystemVersion, and apply that filter to the relevant group assignment in include or exclude mode. Use this property for new rules; Microsoft marks the older osVersion property as deprecated.

Understand what the filter controls

An assignment filter narrows an app, policy, or profile assignment that is already scoped to a group. The filter evaluates device or app properties to decide which members match; it does not change a device’s OS version. Filters can be reused and applied in either include or exclude mode. See Microsoft’s assignment-filter overview.

Choose the filter type that matches the scenario: managed-device filters for enrolled-device management, or managed-app filters for managed-app scenarios such as app protection policies. Workload support varies, so check Microsoft’s supported workloads matrix for the exact platform, workload, and assignment type before deployment.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create and assign an OS-version filter

  1. Open filter creation. In the Microsoft Intune admin center, open the assignment-filter creation workflow and choose the appropriate filter type, managed devices or managed apps. Choose a platform supported by the workload you intend to target. Microsoft documents the workflow in Create assignment filters in Microsoft Intune.
  2. Name the filter clearly. Use a name that identifies both platform and scope, such as iOS major version 18. Add a description if it will help other administrators understand its purpose.
  3. Build the rule. In Rules, use the rule builder or syntax editor. Select operatingSystemVersion, choose a comparison operator, and enter the version value. The rule builder can combine conditions with and or or; use multiple conditions only when the targeting logic requires them.
  4. Review and create. Check the expression and create the filter. If preview is available for the scenario, use it to inspect which devices or apps match before relying on the filter.
  5. Apply it to the assignment. Open the target app, policy, or profile assignment, select the intended group, and choose include or exclude filter mode. Include mode targets matching objects; exclude mode omits matching objects from that assignment.
  6. Validate the scope. Review the resulting assignment and confirm that the expected cohort matches before broad deployment. The filter evaluates reported properties, so its result depends on the version value Intune reports.

Admin-center navigation labels can change; follow the current filter workflow in your tenant if a label differs from Microsoft’s documentation.

Choose the right version rule

Microsoft lists operatingSystemVersion as generally available for managed devices and managed apps. Its supported comparison operators are -eq, -ne, -gt, -ge, -lt, and -le. These compare versions rather than treating the value as an arbitrary text prefix. The property and operator reference documents availability and syntax.

Purpose Operator Example expression
Match an exact version -eq (device.operatingSystemVersion -eq 14.2.1)
Match versions above a build -gt (device.operatingSystemVersion -gt 10.0.22000.1000)
Match a minimum version, including the boundary -ge Use the desired minimum version as the comparison value.
Match versions below a build -lt Use the desired upper boundary as the comparison value.
Match an upper boundary, including the boundary -le (device.operatingSystemVersion -le 10.0.22631.3235)
Exclude one exact version -ne Use the version to omit as the comparison value.

The examples are syntax illustrations from Microsoft’s reference, not recommended or current OS baselines. Use equality when only one reported version should match; use ordered comparisons for a minimum or maximum threshold. Do not assume a partial version string or a range expression behaves like an ordered version comparison.

Account for platform version formatting

For Apple devices, Microsoft notes that operatingSystemVersion does not include the Security Patch Version suffix letter. Leave that suffix out of the filter expression and compare against the version format documented for the property.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not create new rules with the legacy property

Microsoft marks osVersion as deprecated and directs administrators to use operatingSystemVersion for new filters. Existing filters using osVersion continue to work, but the deprecated property cannot be used to create new filters. When updating targeting, translate the intended logic to the current property and supported operators rather than carrying forward legacy syntax.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use managed-app filters for app protection policy cohorts

For an app protection policy scenario, a managed-app filter can select a major OS-version cohort, while the policy’s conditional-launch setting defines the minimum version required within that cohort. Microsoft’s example separates these roles: the filter can select a major release such as iOS 18, and the policy can set a more specific minimum such as 18.2.1. Create the policy with the intended conditional-launch requirement, then apply the matching managed-app filter on the policy’s Assignments page. See Manage device operating system versions with Intune.

This is a targeting pattern, not proof that every app protection policy or assignment type accepts identical filters. Confirm support for the particular policy and platform in Microsoft’s workload support matrix.

Check these scope and enrollment distinctions

  • Managed device versus managed app: select the filter type based on the object properties and assignment scenario being targeted. A device-management assignment and an app-protection assignment may require different filter types.
  • Assignment support: filter behavior depends on workload and assignment type. Microsoft documents, for example, a limitation for Available app assignments in the Android Enterprise personally owned work profile scenario; consult the support matrix for the precise case.
  • Enrollment restrictions: device platform restrictions are a related enrollment control, not the same thing as applying an OS-version filter to an ordinary app, compliance policy, or configuration profile assignment. See Microsoft’s device platform restrictions documentation.
  • Include versus exclude: make the mode match the rollout design. A correct rule in the wrong mode can target the inverse of the intended cohort.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.