Forum Discussion

theunknown's avatar
theunknown
Brass Contributor
Dec 07, 2023

RBAC Intune - Can not see devices

Hi @all :-),

 

I have defined a custom role for our admins in different departments (see screenshot).

 

The administrators are in a group, the group is assigned to that role. Scope groups are assigned (users and devices in the department) and scope tags are set.

 

But the department admin can not access the device list (not authorized). What permission is missing?

 

I hope someone can give me a hint. 🙂

 

 

3 Replies

  • Hello theunknown 

     

    Welcome to the Microsoft community, my name is Recep I'll be happy to help you today.

     

    Please follow the below steps to resolve the issue:

     

    To create a custom role

    1. In the https://go.microsoft.com/fwlink/?linkid=2109431, choose Tenant administration > Roles > All roles > Create.
    2. On the Basics page, enter a name and description for the new role, then choose Next.
    3. On the Permissions page, choose the permissions you want to use with this role.
    4. On the Scope (Tags) page, choose the tags for this role. When this role is assigned to a user, that user can access resources that also have these tags. Choose Next.
    5. On the Review + create page, when you're done, choose Create. The new role is displayed in the list on the Intune roles - All roles blade.

    Copy a role

    You can also copy an existing role.

    1. In the https://go.microsoft.com/fwlink/?linkid=2109431, choose Tenant administration > Roles > All roles > select the checkbox for a role in the list > Duplicate.
    2. On the Basics page, enter a name. Make sure to use a unique name.
    3. All the permissions and scope tags from the original role will already be selected. You can subsequently change the duplicate role's NameDescriptionPermissions, and Scope (Tags).
    4. After you've made all the changes that you want, choose Next to get to the Review + create page. Select Create.

     

    If you still having issue please follow the below link 

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/assign-role 

     

    If I have answered your question, please mark your post as Solved

    If you like my response, please give it a Like :smile:

    Appreciate your Kudos! Proud to contribute! 🙂

     

    • theunknown's avatar
      theunknown
      Brass Contributor
      Found the solution after hours of testing and role comparing:

      Organization: Read was not activated.

Resources