🔐 How to Find and Manage Roles in Microsoft Intune (Endpoint Manager)

 Role-Based Access Control (RBAC) in Microsoft Intune lets you define who can view and manage specific configurations, policies and devices. This guide shows how to locate, review and assign roles in the Microsoft Endpoint Manager admin center.

Where to find roles

  1. Sign in to Microsoft Endpoint Manager admin center.

  2. From the left menu, select Tenant administration.

  3. Open RolesRoles by permission to filter by category or permission.

  4. Use the search box and column filters to quickly find a role or permission.

View roles by permission

  • In Roles by permission, set Category (e.g. ServiceNow) to view related roles.

  • Set Permission (e.g. View Incidents) to list roles that include that permission.

  • Review the results shown:

    • Role display name

    • Role assignment type (built-in or custom)

    • Role name



Filtering by permission helps identify which roles grant access to specific features or integrations.

Review role properties & assign roles

  1. Click a role to open Properties.




  2. Under Basics, read the description and the full list of Permissions.

  3. Go to Assignments to see current assignments.

  4. To create a new assignment:

    • Click Assign.

    • Select a security group as the member.

    • Apply scope tags to limit visibility.

    • Set an assignment duration if required.

Tip: Always assign roles to groups, not individual users — it simplifies management and auditing.




Security & best practices

  • Apply least privilege — only grant required permissions.

  • Use groups and scope tags to segment access.

  • Prefer built-in roles when suitable; create custom roles only when needed.

  • Test new assignments with a dedicated test account before production.

  • Monitor audit logs after changes.

  • Document each assignment (owner, purpose, expiry).

Kommentarer

PopulÀra inlÀgg i den hÀr bloggen

🚀 Force Reinstallation of an Intune App

🚀 Windows Autopilot Self-Deploying Mode — Zero-Touch Setup That Feels Like Magic

Boost Your Graphics Power med GPU-acceleration i Azure Virtual Desktop!