Today we are happy to announce new role-based access control (RBAC) capabilities in Microsoft Endpoint Manager. Starting in Configuration Manager version 2207, you can use Intune RBAC when interacting with tenant-attached devices from the Microsoft Endpoint Manager admin center.
We heard quite a bit of feedback from organizations and the community when it comes to tenant attach. As we analyzed this feedback, we identified gaps, including the lack of RBAC within tenant attach. Specifically, when organizations enabled tenant attach, they noted that viewers had "too much access" and "too much control."
Based on diagnostic data, we know that roughly 35 million devices are tenant attached today. We also recognize that security is top of mind. Thus, we aim to enable more flexibility while increasing security as organizations consume and take steps to attach to the cloud. Based on your feedback, we took action to realize the "least privilege" pillar of Zero Trust for tenant attach functionality. This latest feature addition fully enables Azure Active Directory-only administrative users to manage tenant-attached endpoints from the Endpoint Manager admin center without any need for an on-premises AD account.
We have added a few new settings to the Configuration Manager admin console as well as in the Endpoint Manager admin center to take advantage of the new security configurations for tenant attach device administrators. To get started, enable the configurations below:
When you navigate to the Roles area of the Endpoint Manager admin center, there is a new section for Cloud attached devices. This section gives you some new options that allow you to maintain control over what data administrative users can view and execute on for tenant attach devices. Want to jump straight to this section of the admin center? Visit https://aka.ms/memroles.
Toggle options for turning on or off Cloud attached devices
We hope you enjoy this enhanced security for tenant attached devices. If you have questions, concerns, or feedback, please leave them in the Comments below.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.