Skip to main content

Device Enters Group Trigger

Automatically run an automation when a device is added to a specific group.

Updated this week

Introduction

The device enters group trigger fires when a device is added to one of the groups you select. Use it to run onboarding or configuration tasks automatically whenever a device joins a group — for example, applying a security baseline when a device moves into a production group.

ℹ️ NOTE: Adding non-manual triggers requires either admin status or a role with the Manage automations permission. If you can see the automation but can't add triggers, check your role's permissions with your admin. See Workspace → Permissions for details.


Device Enters Group Trigger

Step Configuration

Select the groups this trigger watches. It fires when a device is added to any of the selected groups.

  1. Check the groups you want to monitor in the group picker.

  2. Use the search field to find specific groups quickly.

  3. Expand parent groups using the arrow to select child groups individually.

Device Enters Group Trigger

You can select as many groups as needed. The trigger fires when a device enters any one of them.

Condition

You must select a condition to save the trigger. Choose All devices or narrow the scope further — for example, adding a Platform condition to only fire for Windows devices entering the group.

For the full condition reference, see Trigger Conditions.

ℹ️ NOTE: The group picker in Step configuration determines which groups the trigger watches for the enter event. The Condition field is an additional filter on the device itself — both must be satisfied for the trigger to fire.

Additional Options

Expand Additional options to set an optional Trigger name and toggle the trigger on or off with the Enabled switch.

  • Trigger name — Replaces the default label on the pipeline trigger card.

  • Enabled — When off, the trigger won't fire. In-progress runs are unaffected.


FAQ

  • Does this trigger fire for devices already in the group when I enable it? No. It only fires on the event — when a device is actively moved into a group. Devices already in the group at the time the trigger is enabled are not pulled in retroactively.

  • What's the difference between the group picker and the Group condition? The group picker defines which groups the trigger watches for the enter event. The Group condition is an additional filter — you can use it to further restrict which devices fire the trigger when the event occurs. For example: watch the Executive group (Step configuration), but only fire for Windows devices (Platform condition).

  • Who can add or edit triggers on an automation? Admin users can always add triggers. Non-admin users need the Manage automations permission on their role, plus access to the automation's group. If an automation has no triggers yet, any user with group access can add the first one.

Did this answer your question?