Skip to content
Intune Role-based Access Controls for Endpoint Privilege Management

Intune Role-based Access Controls for Endpoint Privilege Management

Written By Jitesh Kumar
Last Updated May 22, 2023
Posted In Intune
SHARE

This post helps you to set up Role-based Access Controls for Endpoint Privilege Management in Intune. With Endpoint Privilege Management, you will no longer need to make users local admins. Instead, end users can have standard account privileges and be dynamically elevated to admin privilege for specific admin-approved tasks.

Microsoft Intune Endpoint Privilege Management (EPM) allows your organization’s users to run as a standard user (without administrator rights) and complete tasks that require elevated privileges.

Microsoft enables IT admins to securely support their employees in this new hybrid world with reduced support costs. So they can securely perform tasks such as adding approved apps, printers, or other peripheral devices without needing to contact your IT helpdesk, saving you time and money.

Role-based access control (RBAC) enables Intune Administrators to manage and regulate the permissions granted to individuals for different Intune tasks within your organization. There is a set of twelve (12) built-in Intune roles available, known as RBAC roles including for accessing endpoint privilege management.

Patch My PC

Endpoint Privilege Management uses two policy types that you configure to manage how a file elevation request is handled. Together, the policies configure the behavior for file elevations when standard users request to run with administrative privileges.

Intune Role-based Access Controls for Endpoint Privilege Management

To configure policies for Endpoint Privilege Management, and check the reports, your account must be assigned sufficient permissions from the Intune. Here’s how you can review and assign permissions, Controls for Endpoint Privilege Management.

Intune Role-based Access Controls for Endpoint Privilege Management Fig.1
Intune Role-based Access Controls for Endpoint Privilege Management Fig.1

In the All roles, you will find all the built-in roles, and created custom roles available in the tenant. The Endpoint Security Manage and Endpoint Privilege Manager built-in role manage policies for users or devices.

  • Endpoint Privilege Manager: Manages Endpoint Privilege Management policies in the Intune console.
  • Endpoint Privilege Reader: Endpoint Privilege Readers can view Endpoint Privilege Management policies in the Intune console.
Intune Role-based Access Controls for Endpoint Privilege Management Fig.2
Intune Role-based Access Controls for Endpoint Privilege Management Fig.2

To manage Endpoint Privilege Management, your account must be assigned an Intune role-based access control (RBAC) role that includes the following permission with sufficient rights to complete the desired task:

  • Endpoint Privilege Management Policy Authoring – This permission is required to work with policy or data and reports for Endpoint Privilege Management, and supports the following rights:
    • View Reports
    • Read
    • Create
    • Update
    • Delete
    • Assign
Intune Role-based Access Controls for Endpoint Privilege Management Fig.3
Intune Role-based Access Controls for Endpoint Privilege Management Fig.3

You can add this permission with one or more rights to your own custom RBAC roles, or use a built-in RBAC role dedicated to managing Endpoint Privilege Management:

  • Endpoint Privilege Manager – This built-in role is dedicated to managing Endpoint Privilege Management in the Intune console. This role includes all rights for Endpoint Privilege Management Policy Authoring.
  • Endpoint Privilege Reader – Use this built-in role to view Endpoint Privilege Management policies in the Intune console, including reports. This role includes the following rights for Endpoint Privilege Management Policy Authoring:
    • View Reports
    • Read

Note! You can assign built-in roles, Endpoint Privilege Manager or Reader, to groups without further configuration. You can’t delete or edit the name, description, type, or permissions of a built-in role.

In addition to the dedicated roles, the following built-in roles for Intune also include rights for Endpoint Privilege Management Policy Authoring:

  • Endpoint Security Manager – Manages security and compliance features, such as security baselines, device compliance, conditional access, and Microsoft Defender for Endpoint. This role includes all rights for Endpoint Privilege Management Policy Authoring.
  • Read Only Operator – This role includes the following rights for Endpoint Privilege Management Policy Authoring:
    • View Reports
    • Read
Intune Role-based Access Controls for Endpoint Privilege Management Fig.4
Intune Role-based Access Controls for Endpoint Privilege Management Fig.4

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read