question

Heimdalwk-1551 avatar image
0 Votes"
Heimdalwk-1551 asked LuDaiMSFT-0289 answered

Intuneendpointment auditing role

We have a couple of desktop support techs who are currently working to enroll computers in Intune. We are looking for a way to grant them access to Endpoint Manager with enough permissions to view and audit the list of enrolled devices. Is there a role that would allow this or does a new role need to be created or is this a can't accomplish task?

mem-intune-generalmem-intune-enrollment
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered

@Heimdalwk-1551 If we only want to have a user to view devices, it is suggested to create a custom role and set the permission "managed devices" to "Read".
190338-image.png

Then configure the custom role's assignment. I add a user group in Members and all devices in Scope (Groups).
190359-image.png

190388-image.png

When I use the user included in the user group to login the intune portal, I will view the devices. However, when I click on other page, it will block the access.
190364-image.png

Hope it will give you some ideas.


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



image.png (26.0 KiB)
image.png (25.6 KiB)
image.png (30.6 KiB)
image.png (33.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RahulJindal-2267 avatar image
0 Votes"
RahulJindal-2267 answered

Probably will require a custom role. Did you check the official link?

role-based-access-control


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Heimdalwk-1551 avatar image
0 Votes"
Heimdalwk-1551 answered

I did see this but I wasnt sure what the difference was between All Intune data Intune audit data
I just need users to be able to view the devices that are currently enrolled in Intune but i wasnt sure if the permissions would be all intune data or audit data or something else.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.