Share via

What permissions we need to show and rotate local password of devices?

Gus-0185 125 Reputation points
2026-02-17T16:03:41.34+00:00

Hello,

I'm trying to create a custom role to allow our Helpdesk to see/rotate the local administrator password from Entra or Intune without having to use Intune Administrator Role (too much permisssions). For starter, I am trying to allow them to see the password, but even with the following permissions : microsoft.directory/deviceLocalCredentials/password/read & microsoft.directory/deviceLocalCredentials/standard/read they can't see it (see screenshots below)

User's imageUser's imageUser's image Is it possible to give read / rotate access without giving Intune Administrator? Or at least give read access on either Entra or Intune center. If so, how?

Thank you very much!

Gus

Microsoft 365 and Office | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Marcin Policht 81,395 Reputation points MVP Volunteer Moderator
    2026-02-17T17:45:59.8533333+00:00

    Refer to https://learn.microsoft.com/en-us/intune/intune-service/remote-actions/device-rotate-local-admin-password?pivots=windows

    To run this remote action, use an account with at least one of the following roles:

    • Custom role that includes:
      • The permission Remote tasks/Rotate Local Admin Password
      • Permissions that provide visibility into and access to managed devices in Intune (for example, Organization/Read, Managed devices/Read)

    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.