Microsoft Intune Roles

Eduards 771 Reputation points
2020-12-18T12:06:53.41+00:00

Hello,

I created custom Microsoft Intune Role.

I want that users which will be assigned to this roles can only see Android Dedicated devices and operate only with them.

We also have "Personally owned work-profile" devices in Intune and we want to separate data between Intune administrators.

I tried to configure setting but users that are assigned to custom Android role still see work-profile devices.

Is there some information about what permission should i enable/disable so i achieve my goal?

Thank you!

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,333 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,346 Reputation points
    2020-12-21T07:07:44.297+00:00

    @Eduards Thanks for posting in our Q&A. From your description, I know that you want to get a role that only see Android Dedicated devices and operate only with them. If there is any misunderstanding, feel free to let us know.

    For the user can only manage the test device in Intune portal, here are the detailed steps for a reference:
    1.Create a user group and add a test user to this user group A.
    51865-image.png

    2.Create a device group and add the target device to this device group B.
    51833-image.png

    3.Create a scope tag in Tenant Administrator > Roles > Scope (Tags) and assign to the device group B
    51850-image.png

    4.Create a custom role in Tenant Administrator > Roles > All roles, set Permission for this role, choose Scope tags.
    51923-image.png
    51924-image.png

    5.Choose the custom role we created, select Assignments to add Role Assignment, configure Admin Groups, users in these group will have permissions to manage users/devices in the Scope (Groups), configure Scope groups and select scope tags
    51942-image.png
    51943-image.png

    6.When I login intune portal with the test user, I only see this target device.
    51944-image.png

    The following link for the reference:
    https://learn.microsoft.com/en-us/mem/intune/fundamentals/scope-tags

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful