Role-based access control within Intune itself, a subset of what Microsoft Entra RBAC offers. A role (either built in or custom) is assigned to member groups and limited by scope groups and tags. Entra roles, Intune Administrator for example, sit outside its control.
Also called Intune role-based access control.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Intune RBAC in context, with comparison tables and the common traps.
Terms in this definition
- RBAC
Short for role-based access control: Azure role assignments, inherited downward through scopes, that decide who may perform which actions on resources. Resource location and size are outside its control.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Scope groups
Under an Intune role assignment, the set of users and devices an administrator is permitted to manage.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- Intune Administrator
A highly privileged Microsoft Entra role with complete read and write control over Intune, along with the ability to look after users, groups and devices. In PowerShell and Microsoft Graph its name is Intune Service Administrator; for everyday tasks Microsoft suggests giving people a least-privilege Intune role instead.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- Intune custom role
An Intune RBAC role you assemble from selected permissions so administrators get only what they need. Built-in roles are read-only, but you can copy one and edit the copy as a custom role.
- Scoped permissions
An optional Intune RBAC switch that, once enabled, can't be undone. It keeps permissions granted by separate role assignments with different scope tags from merging.