Forum Discussion
rob_wood_8894
Aug 09, 2022Brass Contributor
Device Groups not working as expected
Hello, Added tags to some of our onboarded devices and created a device group to collect them together, all good. Created a role in endpoints\Roles and assigned it to the device group and an AAD gr...
rob_wood_8894
Aug 11, 2022Brass Contributor
They aren't in any group or role apart from an AAD security group that is assigned to the device group. If i remove them from the AAD group they cannot see any devices in the inventory
yongrheemsft
Microsoft
Aug 11, 2022rob_wood_8894, when you go to Permissions-> Endpoints -> Roles, do you see: "Start using roles?
Role-based access control provides granular options for regulating permissions to portal features and data.
Users with read-only permissions will lose access to the portal until they are assigned one of the new roles through their Azure AD groups.
Users with admin permissions are automatically assigned the Microsoft Defender for Endpoint administrator role with full permissions.
Turn on roles"
or something else?
Thanks,
Yong Rhee - MSFT
Role-based access control provides granular options for regulating permissions to portal features and data.
Users with read-only permissions will lose access to the portal until they are assigned one of the new roles through their Azure AD groups.
Users with admin permissions are automatically assigned the Microsoft Defender for Endpoint administrator role with full permissions.
Turn on roles"
or something else?
Thanks,
Yong Rhee - MSFT
- rob_wood_8894Aug 12, 2022Brass Contributor
yongrheemsft I've followed all of the steps in the microsoft docs. So i have enabled roles and created a role to be assigned to the Device group, as per the docs. I have created an AAD security group and assigned it to the Device group, as per the docs. The device group has two endpoints as per the tagging. When the user is not a member of the group they cannot see any endpoints in the portal. When they are added to the AAD group they can see all of the endpoints in the portal. I was expecting that they should be able to see the two endpoints that are in the device group, as per the docs.
- yongrheemsftAug 12, 2022
Microsoft
rob_wood_8894, RE: "they can see all of the devices in the inventory still, not as expected!!", if the end-user is a part AAD "Global administrator" or "Security Administrator" group, this is expected and by design. Now, if your end-user account is not a part of these groups, please open a Microsoft CSS support ticket for further investigation.- rob_wood_8894Aug 12, 2022Brass ContributorThey are not in any admin groups, i'll raise a ticket