Home

PIM: Assignment of custom roles (e.g. Intune custom roles)

%3CLINGO-SUB%20id%3D%22lingo-sub-1290736%22%20slang%3D%22en-US%22%3EPIM%3A%20Assignment%20of%20custom%20roles%20(e.g.%20Intune%20custom%20roles)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1290736%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20folks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20wonder%20if%20it's%20possible%20to%20assign%20custom%20roles%20with%20the%20privileged%20identity%20management.%3C%2FP%3E%3CP%3EAt%20the%20moment%20i%20would%20like%20to%20assign%20our%20custom%20intune%20roles.%20Is%20this%20possible%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20yyou%20in%20advance.%3C%2FP%3E%3CP%3EPatrick%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1290736%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECustom%20Roles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPIM%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPrivileged%20identity%20management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1290821%22%20slang%3D%22en-US%22%3ERe%3A%20PIM%3A%20Assignment%20of%20custom%20roles%20(e.g.%20Intune%20custom%20roles)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1290821%22%20slang%3D%22en-US%22%3EHi%20Patrick%2C%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20I%20did%20to%20assign%20custom%20roles%20was%20to%20go%20the%20route%20of%20creating%20an%20access%20package%20with%20the%20roles%20assigned%20and%20then%20have%20access%20requested%20via%20that.%20This%20article%20also%20has%20another%20method%20to%20do%20it.%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fprivileged-identity-management%2Fazure-ad-custom-roles-assign%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fprivileged-identity-management%2Fazure-ad-custom-roles-assign%3C%2FA%3E%20I%20hope%20that%20helps.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1294614%22%20slang%3D%22en-US%22%3ERe%3A%20PIM%3A%20Assignment%20of%20custom%20roles%20(e.g.%20Intune%20custom%20roles)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1294614%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F576903%22%20target%3D%22_blank%22%3E%40ChonoN%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20kind%20reply.%3C%2FP%3E%3CP%3EUnfortunatelly%20in%20my%20PIM%20console%20there%20is%20no%20menu%20item%20called%20%22%3CSTRONG%3EAzure%20AD%20custom%20roles%20(Preview)%22%3C%2FSTRONG%3E%26nbsp%3Bas%20mentioned%20in%20the%20MS%20docs%20article.%20%3A%5C%3C%2Fimg%3E%20Is%20this%20an%20option%20in%20your%20tenant%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20you%20describe%20your%20alternate%20approach%20a%20little%20more%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1294763%22%20slang%3D%22en-US%22%3ERe%3A%20PIM%3A%20Assignment%20of%20custom%20roles%20(e.g.%20Intune%20custom%20roles)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1294763%22%20slang%3D%22en-US%22%3EAs%20the%20Intune%20roles%20aren't%20created%20through%20AAD%2C%20but%20through%20Intune%3CBR%20%2F%3E%3CBR%20%2F%3EIt's%20not%20possible%20to%20assign%20them%20through%20PIM.%3CBR%20%2F%3E%3CBR%20%2F%3EAssigning%20custom%20roles%20is%20in%20preview%20indeed%2C%20but%20now%20it%20only%20support%20application%20permissions%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1296072%22%20slang%3D%22en-US%22%3ERe%3A%20PIM%3A%20Assignment%20of%20custom%20roles%20(e.g.%20Intune%20custom%20roles)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1296072%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3BYes%20it's%20an%20option%20in%20mine%20and%20what%20I%20did%20was%20create%20a%20group%20with%20the%20appropriate%20permissions%20and%20access%20levels%20and%20then%20created%20an%20access%20package%20via%20PIM%20so%20that%20when%20someone%20needed%20to%20perform%20those%20task%20they%20will%20activate%20the%20role%20via%20PIM%20and%20be%20added%20to%20group%20and%20then%20upon%20expiration%20be%20automatically%20removed.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hi folks,

 

i wonder if it's possible to assign custom roles with the privileged identity management.

At the moment i would like to assign our custom intune roles. Is this possible?

 

Thank yyou in advance.

Patrick :)

4 Replies
Highlighted
Hi Patrick,

What I did to assign custom roles was to go the route of creating an access package with the roles assigned and then have access requested via that. This article also has another method to do it. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/azure-ad-cust... I hope that helps.
Highlighted

Hi @ChonoN 

 

Thank you for your kind reply.

Unfortunatelly in my PIM console there is no menu item called "Azure AD custom roles (Preview)" as mentioned in the MS docs article. :\ Is this an option in your tenant?

 

Could you describe your alternate approach a little more?

Highlighted
As the Intune roles aren't created through AAD, but through Intune

It's not possible to assign them through PIM.

Assigning custom roles is in preview indeed, but now it only support application permissions
Highlighted

@PatrickF11 Yes it's an option in mine and what I did was create a group with the appropriate permissions and access levels and then created an access package via PIM so that when someone needed to perform those task they will activate the role via PIM and be added to group and then upon expiration be automatically removed.