Event details
Have questions on how to use Microsoft Endpoint Manager to assess your organization’s readiness for Windows 11? Want to know how to monitor the status of a Windows 10 feature update deployment? Curio...
Heather_Poulsen
Updated Jul 21, 2021
ChrisClaytonSTLCC
Jul 21, 2021Brass Contributor
We use a combination of M365 resources as well as SCCM for Windows device management. I want to make sure that our desktop team has what they need to be successful with deploying Windows 11, and not waiting on me as the global admin. Is there a role I need to delegate besides Desktop Analytics and Intune Administrator for them to be able to proceed with all the tools and integrations Microsoft is providing to support this?
David_Mebane
Microsoft
Jul 21, 2021Hi Chris - there are a few options for you. In addition to the Intune Administrator role, you can also use the Policy and Profile Manager Role in Intune for managing Windows Updates. Beyond the Intune Administrator and Policy and/or Profile Manager Role for managing updates, we also recommend using Endpoint Analytics to determine device eligibility. The permissions for Endpoint Analytics are available here: https://docs.microsoft.com/en-us/mem/analytics/overview#permissions
Since you asked about all tools, I will also mention that if your team wants to use the Windows Update for Business deployment service directly, you can use the Windows Update Deployment Administrator in Azure Active Directory (though this does not apply within Endpoint Manager).
Hope this helps!