HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the resources shown in the following table. 

Device2 is a member of Group1 and Group2: No
Device3 is a member of Group2 only: Yes
Device1 No, Device2 No, Device3 Yes.
Pretty sure that's correct since the deviceTrustType is what matters here. Hybrid joined maps to ServerAD so doesn't match either group, and only registered maps to Group2's rule. Someone let me know if I missed something?
Device2 is only in Group1, not both. The group dynamic filters use deviceTrustType so Device2 (AzureAD join) misses Group2 since that's for Workplace devices only. Pretty sure that's right based on what MS docs say, but open to correction if I missed something!
