RBAC roles to view devices in Intune

IntuneUser 171 Reputation points
2022-04-13T10:05:21.66+00:00

Intune admins/Global admin can view devices which have Ownership - "Unknown" in Intune portal.
For those devices, it shows the MDM Authority in Azure AD as - No MDM.

Currently, I am using a custom RBAC role to enable users to view all devices in Intune.
192599-image.png

But with those custom roles, users can view devices which have MDM authority in Azure AD as Intune. The devices which have MDM Authority in Azure AD as - No MDM cannot be viewed.

I would like to know that if there is any pre-defined/custom RBAC role in Intune or Azure which would enable user in viewing the devices with ownership - "Unknown". I would like to enable users to allow only read permission.

Please note : Cloud Device Administrator role in Azure AD cannot be used as that would give users read/write permissions.

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
672 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,569 questions
{count} votes

Accepted answer
  1. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2022-04-14T01:20:52.737+00:00

    @IntuneUser , Thanks for the reply.

    Based on my test, when I grant the following permission, I can see the device without MDM in Azure AD portal. You can grant the organization: read permission to the user to see if it can work.
    192760-image.png
    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful