SOLVED

Permission to manage a group of devices

Copper Contributor

Some of our employees need to manage a small fleet of (approx. 30) AutoPilot/InTune enrolled devices.
We want to allow them to accomplish all remote tasks (only) on these devices (from "Retire" to "Locate device").
How can we achieve that?

(I wish we could simply assign them some built-in role but I don't know which one.)

3 Replies
best response confirmed by ChristineVacher (Copper Contributor)
Solution
What you need is scope tag and a custom role assigned to a dynamic AAD group containing these devices.

Thank you @rahuljindal-MVP.
So, no built-in role :sad:.

I never created custom roles yet. I suppose that I should duplicate a built-in role.
Should I start with Help Desk Operator?

You can use built-in role if it meets your requirement.
1 best response

Accepted Solutions
best response confirmed by ChristineVacher (Copper Contributor)
Solution
What you need is scope tag and a custom role assigned to a dynamic AAD group containing these devices.

View solution in original post