SCCM RBAC role for specific task

Ramesh RK 131 Reputation points
2022-05-31T18:31:22.95+00:00

Hi All

I have special requirement in my SCCM infra on CB 2111.
Need to create couple of RBAC roles to a smaller audience:

ROLE1:

  • Should be able to manage a particular collection; that is adding and removing hostnames to/from the respective collection
  • Should be able to deploy software/patches only to that collection
  • No other permission required

ROLE2:

  • Should be able to view and delete hostnames in Devices
  • Do not need any other permission. Even other nodes in the console can be disabled for them

Need advice / suggestion on creating such RBAC. Kindly assist.

Regards

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 additional answers

Sort by: Most helpful
  1. Amandayou-MSFT 11,051 Reputation points
    2022-06-01T08:22:14.077+00:00

    Hi @Ramesh RK ,

    Agree with Kalyan Sundar, we should create security scope, and copy the full administrator of security roles, according to our requirement, set the tab of collection, set NO in the other tab, add the security role of application administrator, software update manager.

    Here is the screenshot we could refer to:

    207483-61.png

    207491-613.png

    And role 2, we could modify the the full administrator of security roles, set the collection, and any other tabs as NO.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Ramesh RK 131 Reputation points
    2022-07-06T19:27:19.597+00:00

    Thank you @Kalyan Sundar and @Amandayou-MSFT .
    I was able to play with RBAC and was able to get what i want.

    Want to check with guys if i can hide these circled objects? I did create a security scope to specific folder 'ActiveDirectory-Servers', and that listed only this folder; but with that i was not able to access reports

    218323-image.png

    Appreciate if any advice on this please

    0 comments No comments