Intune markers placed on objects and on role assignments, restricting which objects each admin sees. They have no bearing on which devices get a policy; assignments decide that.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Scope tags in context, with comparison tables and the common traps.
Terms in this definition
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Copilot in Intune
Puts Security Copilot inside Intune's admin center. Admins can ask questions of their data in plain English, get policy and device summaries, and have device query KQL drafted for them; it consumes Security Copilot compute units, and scope tags and RBAC still apply.
- Scoped permissions
An optional Intune RBAC switch that, once enabled, can't be undone. It keeps permissions granted by separate role assignments with different scope tags from merging.