Create custom role for Intune

IntuneUser 171 Reputation points
2023-02-25T03:18:25.9466667+00:00

I have the following requirement:

We have 2 admin departments in our organization - Windows and Mobile for MDM.

We would like to setup custom roles or use scope tags such that:

  1. Windows admin - They should be able to manage all aspects(Remote actions, create configuration, compliance policy, etc.) for only Windows devices.
  2. Mobile admin - They should be able to manage all aspects(Remote actions, create configuration, compliance policy, etc.) for only Android and iOS/iPadOS devices.

Windows admin users should not be able to manage Android aspect of the settings and vice-versa.

Is this scenario possible to be created ?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,785 questions
Microsoft Intune Grouping
Microsoft Intune Grouping
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Grouping: The arrangement or formation of people or things in a group or groups.
46 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,666 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,366 Reputation points
    2023-02-27T01:55:52.65+00:00

    @IntuneUser Thanks for posting in our Q&A.

    Of course, you can. I have done the test in my lab. I will share you more details.

    Step1: I create a device group that only includes windows devices.

    User's image

    Step2: I create a user group that I want the user in this group only can see windows devices.

    User's image

    Setp3: I create a scope tag called "windows scope tag" in Tenant administration > Roles > scope tags. In this "windows scope tag", I add the windows device group under "assignments".

    User's image

    Setp4: I create a custom role called "windows role" in Tenant administration > Roles and enable the feature what I want and add "windows scope tag".

    User's image

    Step5: I create a role assignment.

    User's image

    User's image

    Stpe6: When I use the target user signing in intune portal, I can only manage windows devices and I can't see other platform devices.

    User's image

    Hope it will help.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Lu Dai-MSFT 28,366 Reputation points
    2023-02-27T02:20:07.71+00:00

    @IntuneUser This is the double post.

    Thanks for posting in our Q&A.

    Of course, you can. I have done the test in my lab. I will share you more details.

    Step1: I create a device group that only includes windows devices.

    User's image

    Step2: I create a user group that I want the user in this group only can see windows devices.

    User's image

    Setp3: I create a scope tag called "windows scope tag" in Tenant administration > Roles > scope tags. In this "windows scope tag", I add the windows device group under "assignments".

    User's image

    Setp4: I create a custom role called "windows role" in Tenant administration > Roles and enable the feature what I want and add "windows scope tag".

    User's image

    Step5: I create a role assignment.

    User's image

    User's image

    Stpe6: When I use the target user signing in intune portal, I can only manage windows devices and I can't see other platform devices.

    User's image

    Hope it will help.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.