Limit permissions on admins

Brass Contributor

We have a lot of users that needs to be Global Admins to be able to go in and wipe/delete mobile devices in Office 365 (intune).

I want to limit their permissions so that they no longer are Global Admins, but I can not find a description on what permissions they need. Anyone have limited admins that can manage mobile devices in 365?

1 Reply

Limiting Global Admins is a good idea! There are roles driven by Azure AD, have you seen them, if they are relevant like Intune Service Administrator. 


Using the New Role Based Access Controls in Intune


Role-based administration control (RBAC) with Intune


Assigning administrator roles in Azure Active Directory


The first link has a table with Intune Role Permissions.