question

ComputerHabit-1849 avatar image
0 Votes"
ComputerHabit-1849 asked saldana-msft edited

Permissions to Assign deployment profiles

I am working on permissions for Intune. I wanted to use the built in roles for admins to do their work. I've given all permissions I think are necessary however I am having an issue with admins not having the ability to assign policies.

In this case the admin can create a Windows autopilot deployment profile but can not assign the profile to a group.

The error is :

You don't have enough permissions to assign this profile to one or more of your selected groups.

As mentioned the admin can login and create the autopilot profile. They just get an error when assigning it.

mem-intune-generalmem-intune-enrollmentmem-autopilotmem-intune-admin-center
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered

@ComputerHabit-1849 Thanks for posting in our Q&A.

To clarify this issue, we appreciate your help to check some information:
1.Did you use the "Policy and Profile manager" built-in role?
2.If yes, please make sure that you allow the permissions under "Enrollment programs" under this built-in role.
3.Please make sure that you add the target admin user in "Members" and the target device in "Scope (Groups)" in the built-in role's assignments.
We can read the article about role assignments in the following link:
https://docs.microsoft.com/en-us/mem/intune/fundamentals/role-based-access-control#role-assignments

If there is anything update, feel free to let us know.


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

ComputerHabit-1849 avatar image
0 Votes"
ComputerHabit-1849 answered

I am using the "Policy and Profile manager" role.

Under "Enrollment Programs" the permission to assign is there.

180222-image.png




It is assigned to a group for a few days already.


image.png (16.4 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

ComputerHabit-1849 avatar image
0 Votes"
ComputerHabit-1849 answered LuDaiMSFT-0289 commented

Turns out I needed to add All devices to my assignments.

180195-image.png



image.png (9.5 KiB)
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@ComputerHabit-1849 Thanks for your update.

I have done the test in my lab and I add "All devices" in Scope (Groups) as same as you configured. When I also add "All devices" in the autopilot deployment profile, it works well. However, when I add any other specific device group(not "All devices") in the autopilot deployment profile, the error will occur.

For our issue, it is suggested to create a device group and only add this device group to Scope (Groups). Then try to assign the Autopilot profile to the same device group to see if it works.

Scope(groups):
180544-image.png

Windows autopilot deployment profile's assignment:
180508-image.png


0 Votes 0 ·
image.png (17.5 KiB)
image.png (5.7 KiB)

@ComputerHabit-1849 Haven't heard from you for some time, I am currently standing by for further update from you and would like to know how things are going. If you have any questions or concerns on the recent information I've provided you, please don't hesitate to let me know.

0 Votes 0 ·