Hi there,
I'd like to know if it's possible to configure smart groups in a way to apply a specific smart group ONLY when a device has just been enrolled. The issue we're having is Sophos Endpoint has 2 custom mobileconfig policies. 1 for MacOS Monterey and 1 for MacOS Ventura.
I have a simple smart group setup that separates Monterey and Ventura devices

Problem is, if someone were to upgrade their OS, their current Sophos installation will still be installed but the configurations for Sophos mobileconfig for Monterey will be removed and replaced with the Ventura mobileconfig. Since the configs are applying AFTER Sophos has already been installed this would undoubtedly break Sophos' permissions on the machine.
Is there any way to have a smart group only apply immediately after enrolment and no other time? This is to make sure that when devices with Ventura installed have been freshly installed that they get the Ventura configuration only and not devices that upgrade from Monterey to Ventura.




