Intune – Additional permissions for the Endpoint Security Manager role

As you know, you can delegate permissions to allow certain administrative or management tasks using RBAC (Role Based Access Control) on Intune/Endpoint Configuration Manager.

Well, new permissions have been added to the Endpoint Security Manager role:

  • Initiate Configuration Manager action
  • Microsoft Defender ATP
  • Reboot now
  • Remote lock
  • Rotate BitLockerKeys (preview)
  • Rotate FileVault key
  • Shut down
  • Sync devices

If you are using the built-in Endpoint Security Manager role, you have nothing to do, except maybe some communication to the delegates.

If you are using custom role to delegate permissions, you may have to update your custom role to reflect these new permissions.

image_thumb

Intune – you can now get details about devices in co-management configuration

As you know, you can have System Center Configuration Manager (SCCM)/Endpoint Configuration Manager (on-premises) working in some sort of hybrid...

Read More

Intune – You can now define update locations for Windows Defender

As you know you can control some settings of Windows Defender through Intune/Endpoint Configuration Manager.

Read More

Intune – You can now launch script from SCCM from the Intune portal

If you are using System Center Configuration Manager Current Branch (SCCM Current Branch) version 2006 in a co-management configuration with...

Read More