the Built-in Endpoint Security Manager role is assigned to two AD groups, but this role for whatever reason cannot modify policy?

Winston M. Gonzalez 0 Reputation points
2023-04-03T19:56:53.9266667+00:00

In Intune the built-in Endpoint Security Manager role, is assigned to two AD Groups SG-xxx-MDATP-Administrators and SG-xxx-MDATP-Operator, this role for whatever reason cannot modify policy?

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-04-04T02:09:11.95+00:00

    @Winston M. Gonzalez, Thanks for posting in Q&A.

    For the built-in Endpoint Security Manager Role, it manages security and compliance features, such as security baselines, device compliance, conditional access, and Microsoft Defender for Endpoint.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/role-based-access-control#built-in-roles

    Could you confirm if you are modifying device configuration policy? Based on my checking, for device configuration policy, it only has Read permission.
    User's image

    If you want to manage policy, maybe you can consider the built in Role "Policy and Profile Manager"

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.