Forum Discussion
Steve Whitcher
Aug 13, 2020Bronze Contributor
What admin role grans permission to view devices' bitlocker recovery keys?
Which of the standard admin roles is required to view bitlocker recovery keys for a device in intune?
Thijs Lecomte
Feb 03, 2021Bronze Contributor
I agree, it's a pain 😕
Ken Rappold
Feb 03, 2021Brass Contributor
Thijs Lecomte and overpermissioned when all we need is L1 to access BitLocker keys for users.
- Joshua BinesMay 19, 2021Iron ContributorThey do have the helpdesk role available for AU but we just need to the ability to add the devices which will come in time i'm sure 🙂
- Thijs LecomteMay 13, 2021Bronze ContributorIn order to fully solve this issue, we need to have devices support in AU with custom roles. Let's hope it's here sooner rather than later
- Joshua BinesMay 11, 2021Iron ContributorSeems like Azure AD Administrative Units are not helpful in this space either.
https://feedback.azure.com/forums/169401-azure-active-directory/suggestions/41324467-add-devices-to-administrative-units - creatoni4Mar 30, 2021Copper ContributorThis is real pain.
especially when you have scopes separation in Endpoint Manager and you use RBAC to separate offices equipment.
Of course i cannot grant helpdesk admins on AAD.... that definitely not LEAST Privilege.
That AAD issue BTH. There is no possible to assign role to scope ... there is no scopes at all.