Forum Discussion
BMO_Rob
Jan 20, 2023Copper Contributor
Autopatch Admin Role
I want to onboard a new Intune administrator who should only have permissions to manage Autopatch, e.g. enroll devices in the service, move devices between rings, monitor announcements, submit autopa...
Andre Della Monica
Microsoft
Feb 02, 2023Thanks for the feedback here, BMO_Rob! The default roles Autopatch requires are: 1) Azure Global Admin and 2) Intune Service Administrator, however, you can add less-privileged user accounts into the Modern Workplace Roles - Service Administrator Azure AD group (this group is created during the Autopatch tenant enrollment process). User accounts part of this group can perform the operations you described above. See more details to what I'm saying here in this doc: https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/deploy/windows-autopatch-register-devices#built-in-roles-required-for-device-registration
BMO_Rob
Feb 03, 2023Copper Contributor
Thanks Andre Della Monica
This is very helpful.