Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
This feature is in public preview. For more information, see Public preview in Microsoft Intune.
This article describes role-based access control (RBAC) permissions, scope tag behavior, and Multi Admin Approval for deployment plans and deployments. For general information about Intune RBAC, see Role-based access control with Microsoft Intune.
Deployment plan permissions
The following permissions are available for deployment plans:
| Permission | Action | Description |
|---|---|---|
| Deployment plan | Create (C) | Create a plan |
| Deployment plan | Read (R) | Read a plan |
| Deployment plan | Update (U) | Edit or modify a plan |
| Deployment plan | Delete (D) | Delete a plan |
Intune built-in roles include deployment plan permissions that align with each role's management category, such as device configurations or mobile apps, and its supported actions. For example, the Policy and Profile Manager role has CRUD permissions for device configurations, so it also has CRUD permissions for deployment plans.
Deployment plan permissions are included in the following built-in roles:
| Built-in role | Deployment plan permissions |
|---|---|
| Application Manager | Create, Read, Update, Delete |
| Read Only Operator | Read |
| Endpoint Security Manager | Create, Read, Update, Delete |
| Help Desk Operator | Read |
| Policy and Profile Manager | Create, Read, Update, Delete |
| School Administrator | Create, Read, Update, Delete |
Deployment permissions
Deployments don't have a dedicated permission. Permissions are based on the selected payload's category.
| Action | Payload type | Required permission |
|---|---|---|
| Create a deployment | Device configuration | Read and Assign permissions for the Device configurations category |
| Create a deployment | Apps | Read and Assign permissions for the Mobile apps category |
| View a deployment | Device configuration | Read permission for the Device configurations category |
| View a deployment | Apps | Read permission for the Mobile apps category |
Scope tags
Scope tags control object visibility in Intune. Administrators can only view objects that have scope tags within their assigned scope.
| Action | Scope tags enforced | Behavior |
|---|---|---|
| View deployments in the Deployments list | Yes | An administrator can only see deployments whose payload is within the administrator's scope. |
| View plans in the Deployment plans list | Yes | An administrator can only see plans within the administrator's scope. |
| Select a payload when creating a deployment | Yes | The payload list only displays payloads within the administrator's scope. |
You can assign scope tags directly to deployment plans. You can't assign scope tags to deployments. Because apps and policies support scope tags, the selected payload is the visibility control plane for its deployment.
For general information, see Use scope tags for distributed IT.
Multi Admin Approval
Intune deployments support Multi Admin Approval (MAA). When an MAA access policy is configured for a policy type that deployments support, Intune enforces the approval flow. For example, if you create a deployment for a Windows app and an access policy protects the App Windows platform, the deployment requires approval.
The following deployment actions trigger an MAA approval flow:
- Create
- Resume
- Cancel
- Delete
Note
An MAA approver needs Read permission for the payload to access the deployment properties link in the approval request.
When a deployment creation request requires approval, the deployment doesn't appear in the Deployments list until the approval is complete.
For more information, see Use Multi Admin Approval in Intune.