Skip to content
Control Organizational Messages using Intune RBAC Role

Control Organizational Messages using Intune RBAC Role

Written By Jitesh Kumar
Last Updated May 15, 2023
Posted In Intune
SHARE

Let’s learn how you can control Organizational Messages using Intune RBAC. Role-based access control (RBAC) enables effective management of access privileges for your organization resources, specifying both the individuals who are granted access and the actions they are permitted to perform.

Organizational messages in Microsoft Intune offer the capability to utilize branded messages for the purpose of informing individuals about their organization or preparing them for new roles. They also serve as a means to notify users about organizational updates and training opportunities.

By leveraging these features, organizations can effectively communicate important information and facilitate learning within their workforce. Starting with Intune Service release 2304, Additional permissions to support administrators in controlling the delivery of organization messages.

There are twelve (12) built-in Intune roles (RBAC roles). You can create custom Intune roles if none of the provided roles supports your scenario. Without any additional configuration, it is possible to allocate built-in roles to groups. However, it is not feasible to modify the name, description, type, or permissions of a built-in role or remove it.

Patch My PC

To create organizational messages in Microsoft Intune, you must be assigned one of the following roles, Azure AD Global administrator, Intune administrator, Organizational messages manager (Intune Built-in role), or Organizational messages writer (Azure AD role).

Control Organizational Message from Intune RBAC Role

In order to create, edit, or assign roles, your Azure AD account must possess one of the following permissions: Global Administrator or Intune Service Administrator (also referred to as Intune Administrator).

Control Organizational Message from Intune RBAC Role Fig.1
Control Organizational Message from Intune RBAC Role Fig.1

In the All roles, you will find all the built-in roles, and created custom roles available in the tenant. The Organizational Messages Manager built-in role manages organizational messages in Intune console.

Control Organizational Message from Intune RBAC Role Fig.2
Control Organizational Message from Intune RBAC Role Fig.2

Here is how you can check the permissions by navigating to the roles by clicking on Properties. Here you can also be able to get the details of permissions added for the role.

You can assign built-in roles, Organizational Messages Manager, to groups without further configuration. You can’t delete or edit the name, description, type, or permissions of a built-in role.

ActionsDescriptions
CreateCreate organizational message
ReadRead organizational message delivery results
Update organizational message controlDetermines who can change the Organizational Messages toggle to allow or block Microsoft direct messages
UpdateUpdate organizational message
DeleteAbility to delete organizational message
AssignAssign the organizational message to a group
Table 1 – Control Organizational Message from Intune RBAC Role
Control Organizational Message from Intune RBAC Role Fig.3
Control Organizational Message from Intune RBAC Role Fig.3

You can duplicate built-in roles to create, edit, or assign Intune roles. Here’s how you can duplicate Intune RBAC roles for Organizational Messages and manage roles under Organizational Messages custom role section, Duplicate Intune RBAC Roles.

You can assign a built-in or custom role to an Intune user, choose the built-in role (Organizational Messages Manager) you want to assign >  Assignments > + Assign.

Control Organizational Message from Intune RBAC Role Fig.4
Control Organizational Message from Intune RBAC Role Fig.4

On the Basics page, enter an Assignment name and optional Assignment description, and then choose Next. On the next screen Admin Groups, select the group that contains the user you want to give the permissions. Choose Next and complete the Assignment.

The Update organizational message control RBAC permission for organizational messages, determines who can change the Organizational Messages toggle to allow or block Microsoft direct messages. This permission is also added to the Organizational Messages Manager built-in role.

Intune RBAC Strategic options – Video

In this video, we will explain Intune RBAC Strategic Options | Role-Based Access Controls | Scope Groups | Intune Objects | Roles.

Control Organizational Message from Intune RBAC Role

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read