Forum Discussion
Luis_Antonio_Marquez
Jan 21, 2021Copper Contributor
Powershell and credentials
Probably this is a very common topic. I would like to supply some scripts to the support team, that should run with very high privileges, but I don't want them to have those privileges. Can anyone h...
Luis_Antonio_Marquez
Jan 22, 2021Copper Contributor
Thijs Lecomte , first thanks for your answer.
They are tasks related to the user and device management. Usually, they would require Intune Administrator, Device Administrator, User Administrator roles but definitely, they are too powerful to be assigned. Now they are working using PIM, but anyway I feel it would be great to let an application do the job with appropriate permissions, and let the Support Team work with minimum privileges. That said, any recommendations are very welcomed. I feel a bit lost.
Thijs Lecomte
Jan 23, 2021Bronze Contributor
Have you looked into scope tagging for Intune?
https://tech.nicolonsky.ch/intune-scope-tags-rbac-explained/
I use it for this scenario exactly at multiple customers.
Some admins only have to view data within Intune
https://tech.nicolonsky.ch/intune-scope-tags-rbac-explained/
I use it for this scenario exactly at multiple customers.
Some admins only have to view data within Intune