Skip to content
Intune Read-Only Admin and Scoped Admin Console Experience

Intune Read-Only Admin and Scoped Admin Console Experience

Written By Anoop C Nair
Last Updated August 9, 2024
Posted In Intune
SHARE

Let’s discuss the Intune Read-Only Admin and Scoped Admin Console Experience. This post continues my previous post Intune Admin RBAC Implementation Guide, with Scope tags and Scope groups.

This post will teach you the Intune read-only admin experience after implementing the Role-Based Access Control(RBAC) solution with scope tags and scope groups.

 Intune Read-Only users can manage devices or parts of their Scope Groups. The configuration profiles blade provides a classic view experience for these users.

The read-only users have view access to Overview, Properties, Assignments, Device status, User status, and Per-setting status.

Patch My PC

Intune RBAC Strategic options – Video

In this video, we will explain Intune RBAC Strategic options | Role-Based Access Controls | Scope Groups | Intune Objects | Roles.

Intune Read-Only Admin and Scoped Admin Console Experience – Video 1

Scenarios –  Intune Read-Only Admin and Scoped Admin

I have explained both the following scenarios in the video tutorial below.  This video will also be published on the video blog https://howtomanagedevices.com/. You can see two Intune admin scenarios explained in this post. The following are the scenarios:

#1 – The first scenario is of an Intune Admin called Santy, and she is a Read-Only admin. She can view all the intune objects for a particular tenant. She can consider all the scoped things in Intune, given those permissions.

#2—The second scenario involves an Intune-scoped admin console access experience. Rateesh is an Intune admin for one of the office locations in Mumbai. He has full access to the Mumbai location’s devices and profiles (+ policies), but he can’t view any other scoped objects in Intune.

Intune Read-Only Admin and Scoped Admin Console Experience - Fig.1
Intune Read-Only Admin and Scoped Admin Console Experience – Fig.1

Scope Tag Filtering Effect – Intune Portal

You can see the experience of scope tag filtering for Intune scoped admin in the following screenshot. Intune’s read-only admin (in the above scenario) has access to all the Intune objects.

As you can see, Intune Read-Only admins can view Four(4) Profiles in the Intune console, but Intune-scoped admins can view only three(3) profiles.

However, the scoped admin can deploy or assign these three policies to his scope group (Mumbai Devices and Users) and change the settings of all three(3) device configuration profiles.

This difference is because of scoped objects. Scoped Admin can only view:

  • #1 – Objects scoped to Mumbai
  • #2 – Non-Scoped Objects
Intune Read-Only Admin and Scoped Admin Console Experience - Fig.2
Intune Read-Only Admin and Scoped Admin Console Experience – Fig.2

This Intune scope filtering will work for Devices and all the other supported objects I mentioned in the previous post. A scoped admin can view and administrate only one device scoped for his location, and an Intune Read-only admin can view two devices.

Video Experience – Intune Read-Only Admin and Scope admin

This video tutorial will give you an experience of two different Intune Admin roles.

  • Intune Read-Only Admin
  • Intune Scoped Admin
Intune Read-Only Admin and Scoped Admin Console Experience – Video 2

Where can I check the permissions of an Intune Admin?

Intune troubleshooting is always a bit different from SCCM troubleshooting. SCCM RBAC troubleshooting can be done using the RBA tool. However, in Intune RBAC, troubleshooting and permission issues can be reviewed using the following method.

  1. Login to Azure Portal with Intune Admin ID which you want to review the permissions
  2. Click on the Roles options from Intune Blade.
  3. Click on the My Permissions from the Monitor section
  4. Check out the permissions – Resource & Permission table on the right side of the blade
  5. Click on the EXPORT button to export all the permissions to a CSV format

Resource

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His primary focus is Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 6 comments

  1. I checked your post, for now, I want to see this feature working for managed devices. I configured all you mentioned in the post but it still doesn’t work. A restricted admin can see all my devices. I manually assigned a Tag for some devices and configured that tag for a restricted group of admins, but these restricted admins can still see all the devices I have in Intune (but not manage all of them). I just want to show the tagged manage devices to them. As you mentioned in the post, could it be that this feature is not working for managed devices for now?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read