MEM - Roles - Just manage applications

Yop 81 Reputation points
2021-06-09T14:02:01.18+00:00

Hi Everyone,

I would like to have a role in MEM to allow people just to create, deploy applications (Win32 App, MSI LOB app) read deployment report= manage applications.

Is the MEM role Application Manager enought for this because it does not seems to allow me to create an application into Intune.

Thanks a lot for your help,

Regards.

Microsoft Security | Intune | Application management
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Lu Dai-MSFT 28,501 Reputation points
    2021-06-10T04:39:11.25+00:00

    @Yop Thanks for posting in our Q&A.

    For this issue, I have done the test in my lab. In my test, I add the Application Manager role to my test user. When I login and try to deploy an app, it succeeded. The following are my steps can be a reference.
    1.Create a user group and a device group.
    104055-image.png

    104101-image.png

    2.Create an assignment to Application Manager role in Tenant administration > Roles
    Members: All users in the listed Azure security groups have permission to manage the users/devices that are listed in Scope (Groups).
    Scope (Groups): All users/devices in these Azure security groups can be managed by the users in Members.
    In my test, I add the user group to Members and add device group to Scope (Groups).
    104016-image.png

    104017-image.png

    104033-image.png

    3.Login MEM with the user account included in the user group and try to deploy an app to the device group. It shows success.
    104034-image.png

    Hope it will help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.