SOLVED

Scope tags & apps

%3CLINGO-SUB%20id%3D%22lingo-sub-1416018%22%20slang%3D%22en-US%22%3EScope%20tags%20%26amp%3B%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1416018%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI%20was%20testing%20some%20configurations%20with%20scope%20tags%20and%20apps.%3C%2FP%3E%3CP%3EThe%20setup%20is%20straight%20forward%2C%20I%20have%203%20scope%20tags%20based%20upon%20security%20groups%20containing%20the%20devices%20to%20represent%20a%20region.%3C%2FP%3E%3CP%3EPrior%20to%20starting%20with%20the%20scope%20tags%2C%20there%20were%20already%20apps%20imported%20(Managed%20Google%20Play%20%26amp%3B%20Apple%20App%20Store).%20These%20are%20all%20assigned%20to%20the%20default%26nbsp%3Bscope%20tag.%3C%2FP%3E%3CP%3ENow%20when%20I'm%20logged%20as%20a%20delegated%20admin%20which%20only%20has%20permissions%20to%20add%20apps%20for%20a%20region%2C%20defined%20by%20the%20scope%2C%20I%20cannot%20see%20these%20apps%20which%20is%20expected%20because%20it's%20not%20shown%20(assigned)%20for%20that%20scope%20(region).%20When%20I%20want%20to%20add%20one%20of%20these%20apps%20that%20are%20already%20imported%2C%20I%20see%202%20different%20scenarios%3A%3C%2FP%3E%3CUL%3E%3CLI%3EImport%20from%20Apple%20App%20Store%3A%20The%20app%20is%20imported%20in%20this%20scope%20and%20can%20be%20assigned.%20With%20the%20Intune%20Admin%20I%20see%202%20instances%20of%20the%20app%2C%20one%20for%20the%20default%20scope%20and%20one%20for%20the%20regional%20scope.%20This%20is%20not%20blocking%20but%20confusing...%3C%2FLI%3E%3CLI%3EImport%20from%20Managed%20Google%20Play%3A%20As%20the%20app%20is%20already%20approved%2C%20there%20is%20no%20way%20to%20continue.%20For%20the%20regional%20admin%2Foperator%20there%20is%20nothing%20available%20to%20import%20the%20app%20again%2C%26nbsp%3Bas%20the%20interface%20does%20not%20allow%20you%20to%20do%20anything.%20This%20is%20very%20confusing%20(and%20annoying)%20as%20the%20regional%20operator%20does%20not%20have%20any%20way%20to%20set%20any%20assignment%20for%20the%20app%20for%20the%20scope%20of%20devices.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EI've%20been%20thinking%20about%20some%20workarounds%20for%20this%3A%3C%2FP%3E%3CUL%3E%3CLI%3Ecreating%20a%20process%20around%20this%2C%20but%20that%20doesn't%20resolve%20the%20confusing%20issue%20for%20managed%20Google%20Play%20apps%3C%2FLI%3E%3CLI%3Ecreating%20a%20delegation%20app%20admin%20which%20includes%20all%20the%20scopes%20so%20that%20at%20least%20the%20regional%20admins%20can%20see%20the%20apps.%20This%20isn't%20perfect%20either%20in%20my%20opinion%20as%20it%20would%20conflict%20somewhat%20with%20the%20scoped%20setup.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EHas%20anyone%20ever%20come%20across%20such%20a%20use%20case%20or%20would%20like%20to%20share%20any%20thoughts%20on%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EBart%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1416018%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESoftware%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1416513%22%20slang%3D%22en-US%22%3ERe%3A%20Scope%20tags%20%26amp%3B%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1416513%22%20slang%3D%22en-US%22%3EYou%20raise%20a%20very%20valid%20point%20and%20for%20the%20Managed%20Google%20Play%20store%2C%20I%20don't%20think%20there%20is%20currently%20a%20way%20around%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20recommend%20that%20a%20'delegated%20admin'%20doesn't%20add%20any%20apps%20from%20the%20Managed%20Google%20Play%20Store%2C%20but%20instead%20requests%20it%20from%20a%20global%20IT%20admin%20who%20oversees%20the%20Intune%20environment.%3CBR%20%2F%3EThis%20ensures%20that%20one%20person%20still%20has%20the%20overview%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1418972%22%20slang%3D%22en-US%22%3ERe%3A%20Scope%20tags%20%26amp%3B%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1418972%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20insights!%3C%2FP%3E%3CP%3EI%20was%20thinking%20along%20the%20same%20path%20in%20regards%20for%20adding%20apps%20as%20there%20is%20no%20technical%20option%20to%20implement%20this%20otherwise.%3C%2FP%3E%3CP%3E*edit*%3C%2FP%3E%3CP%3EI%20also%20noticed%20that%20when%20importing%20a%20new%20app%20from%20Managed%20Google%20Play%20by%20a%20delegated%20admin%20in%20the%20scope%2C%20that%20this%20app%20is%20assigned%20the%20default%20scope%20tag%20and%20is%20only%20visible%20by%20the%20Intune%20admin.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20also%20playing%20with%20the%20app%20assignment%20for%20iOS%2C%20because%20even%20though%20it's%20possible%20to%20import%20the%20app%20again%20in%20the%20delegated%20scope%20and%20getting%202%20instances%20in%20the%20Intune%20admin%20view%2C%20it%20isn't%20clear%20to%20me%20what%20the%20result%20would%20be%20when%20the%20assignment%20in%20required%20enforced%20by%20the%20global%2FIntune%20admin%20vs%20assignment%20by%20the%20delegated%20admin.%20For%20the%20first%20results%20it%20looks%20like%20the%20assignment%20from%20the%20delegated%20admin%20has%20higher%20precedence%2C%20but%20I%20haven't%20tested%20all%20the%20scenario's%20yet...%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi,

I was testing some configurations with scope tags and apps.

The setup is straight forward, I have 3 scope tags based upon security groups containing the devices to represent a region.

Prior to starting with the scope tags, there were already apps imported (Managed Google Play & Apple App Store). These are all assigned to the default scope tag.

Now when I'm logged as a delegated admin which only has permissions to add apps for a region, defined by the scope, I cannot see these apps which is expected because it's not shown (assigned) for that scope (region). When I want to add one of these apps that are already imported, I see 2 different scenarios:

  • Import from Apple App Store: The app is imported in this scope and can be assigned. With the Intune Admin I see 2 instances of the app, one for the default scope and one for the regional scope. This is not blocking but confusing...
  • Import from Managed Google Play: As the app is already approved, there is no way to continue. For the regional admin/operator there is nothing available to import the app again, as the interface does not allow you to do anything. This is very confusing (and annoying) as the regional operator does not have any way to set any assignment for the app for the scope of devices.

I've been thinking about some workarounds for this:

  • creating a process around this, but that doesn't resolve the confusing issue for managed Google Play apps
  • creating a delegation app admin which includes all the scopes so that at least the regional admins can see the apps. This isn't perfect either in my opinion as it would conflict somewhat with the scoped setup.

Has anyone ever come across such a use case or would like to share any thoughts on this?

 

Thanks,

Bart

2 Replies
Solution
You raise a very valid point and for the Managed Google Play store, I don't think there is currently a way around it.

I would recommend that a 'delegated admin' doesn't add any apps from the Managed Google Play Store, but instead requests it from a global IT admin who oversees the Intune environment.
This ensures that one person still has the overview
Highlighted

@Thijs Lecomte Thanks for your insights!

I was thinking along the same path in regards for adding apps as there is no technical option to implement this otherwise.

*edit*

I also noticed that when importing a new app from Managed Google Play by a delegated admin in the scope, that this app is assigned the default scope tag and is only visible by the Intune admin.

 

I'm also playing with the app assignment for iOS, because even though it's possible to import the app again in the delegated scope and getting 2 instances in the Intune admin view, it isn't clear to me what the result would be when the assignment in required enforced by the global/Intune admin vs assignment by the delegated admin. For the first results it looks like the assignment from the delegated admin has higher precedence, but I haven't tested all the scenario's yet...