How to disable locate device for some admins?

zaneb hayes 0 Reputation points
2023-03-25T08:54:46.3033333+00:00

Hi experts,

We need to add some users to be Intune admin, but for security reason, we don't want these users to be able to use the locate device option. How can this be achieved?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,713 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Erkan Sahin 830 Reputation points
    2023-03-25T12:52:09.84+00:00

    To prevent Intune admins from being able to locate devices, you can modify their admin roles to remove the "Device Management" permission.

    Here are the steps:

    1. Sign in to the Microsoft Endpoint Manager admin center (https://endpoint.microsoft.com) with an account that has the Global Administrator or Intune Service Administrator role.
    2. In the left navigation pane, go to "Roles > All roles".
    3. Select the admin role that you want to modify.
    4. In the "Permissions" tab, expand the "Device Management" section.
    5. Clear the "Locate devices" permission checkbox.
    6. Click "Save" to save the modified admin role.

    After you have modified the admin role, the users assigned to that role will no longer be able to locate devices.

    Please mark this answer if it helps :-)

    0 comments No comments