We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and MDM
  2. Intune RBAC and scope tags
Intune role-based access control, UAE

Microsoft says do not use Global Administrator to manage Intune. Almost every tenant we look at does.

Intune has nine built-in roles, custom roles, scope groups that limit which devices an administrator can manage, and scope tags that limit which objects they can see. Used together they express least privilege properly. Used not at all, every Intune administrator can do everything to everyone.

Book an Intune permissions reviewSee the roles and how scoping works
Microsoft Intune role-based access control and scope tags in the UAE
  • Nine built-in rolesPlus custom roles and Cloud PC roles
  • Three partsMembers, scope groups and scope tags
  • IncrementalMultiple assignments add permissions together
  • 10s or 15 minPIM elevation timing, depending on method
How it works

Seven things that decide whether your Intune permissions mean anything.

Microsoft describes Intune role-based access control as granting granular permissions so administrators can perform their assigned tasks on only the users and devices they should manage. Each role specifies permissions composed of management categories such as device configuration or audit data, and actions such as read, write, update and delete.

Global Administrator is explicitly not the answer

Microsoft states it plainly: do not use the Global Administrator role in Intune, and it does not recommend using it to administer or manage Intune. Some features do require it, with mobile threat defence connectors given as an example, and the guidance there is to use it only when necessary and remove it when the task is complete.

Intune Administrator is also too much for daily work

Microsoft describes the Intune Administrator role as granting global read and write permissions across Intune, classified as a privileged role, and states that while its scope is narrower than Global Administrator it still exceeds what is needed for almost all day-to-day tasks. Its guidance is not to use it for routine administration. In Graph and PowerShell it appears as Intune Service Administrator.

Nine built-in roles, each for a real job

Application Manager, Endpoint Privilege Manager and Reader, Endpoint Security Manager, Help Desk Operator, Intune Role Administrator, Policy and Profile Manager, Read Only Operator and School Administrator. Where a Windows 365 subscription exists, Cloud PC Administrator and Cloud PC Reader appear as well. Most organisations need three or four of them and use none.

Scope groups limit which devices an administrator touches

Scope groups define the groups of users and devices an administrator with a role assignment can manage. Microsoft gives an explicit instruction here: to ensure administrators with a role cannot target all users or all devices, do not select add all users or add all devices. That single choice is the difference between a scoped helpdesk and an unscoped one.

Scope tags limit which objects an administrator can see

Freeform text values an administrator defines and adds to a role assignment. Microsoft distinguishes two effects: a scope tag on the role controls visibility of the role itself, while a scope tag in a role assignment limits visibility of Intune objects such as policies, applications and devices to administrators in assignments carrying a matching tag.

Three monitoring views, and nobody uses them

My permissions shows the effective permissions of the signed-in user. Roles by permission shows which role assignments and groups grant a specific permission. Admin permissions takes a named account and shows the complete list of permissions it currently holds. That last one answers the question an auditor asks, in about thirty seconds.

Just-in-time elevation, with two different timings

Two supported methods. A Privileged Identity Management policy on the Entra Intune Administrator role, where Microsoft states elevation typically happens within 10 seconds. Or Privileged Identity Management for Groups with an Intune role assignment, where elevation typically takes up to 15 minutes to apply. That difference matters when somebody is elevating during an incident.

The behaviour that quietly widens access

Two role assignments with different scope tags can grant more than either was meant to.

Microsoft documents this directly, and it is the single most surprising thing about Intune role-based access control.

  • Quoted: permissions are incremental where two or more roles grant permissions to the same object. A user with read from one role and read and write from another has an effective permission of read and write, assuming the assignments target the same scope tags.
  • Quoted: when an administrator has multiple role assignments that use different scope tags, this behaviour can result in broader access than intended. That is not a defect, it is how the model composes, and it is not obvious from either assignment viewed alone.
  • Microsoft has published an opt-in preview setting that changes how permissions apply so each role assignment permissions are contained to its own scope tag context, with steps to evaluate the impact on your tenant before enabling it.
  • The practical implication is that reviewing role assignments individually tells you very little. The Admin permissions view, which shows the complete effective permission list for a named account, is the only reliable way to answer what somebody can actually do.
Ask us to run an effective permissions review
How we approach it

Four things that make an Intune permissions model hold.

This is a control that costs a few days to implement and is almost never implemented, because everything works without it right up until the moment it matters.

We start from effective permissions, not from role names

The Admin permissions view takes a named account and shows the complete list of permissions it currently holds. Because permissions are incremental across assignments, and because different scope tags across assignments can widen access further than intended, reading the role names tells you what somebody was meant to have rather than what they have.

We scope by group and by tag, not by one or the other

Scope groups limit which users and devices an administrator can manage. Scope tags limit which policies, applications and devices they can see. They answer different questions and most organisations that attempt scoping use only the first. The instruction Microsoft gives is specific: do not select add all users or add all devices.

We get the broad Entra roles out of daily use

Microsoft says not to use Global Administrator for Intune, and not to use Intune Administrator for routine administration. Where a feature genuinely needs one, such as certain mobile threat defence connectors, the guidance is to elevate for the task and remove it afterwards. Privileged Identity Management makes that practical rather than aspirational.

We check the exclude group behaviour, which trips people up

Microsoft states that an exclude group used in a policy or application assignment needs to be either nested in one of the role assignment scope groups, or separately listed as a scope group in the role assignment. Get that wrong and exclusions silently fail to apply, which is a very hard problem to diagnose from the symptom.

Where this matters most

Six UAE situations where Intune scoping stops being optional.

The trigger is usually organisational rather than technical: a merger, an outsourced helpdesk, a regulated business unit, or an auditor asking who can wipe a device.

A group with several business units under one tenant

Scope groups and scope tags together let each unit administrator manage and see only their own devices and policies. Without them, an administrator in one subsidiary can view and modify configuration belonging to another, which becomes a governance question the first time somebody notices.

An organisation using an outsourced or offshore helpdesk

The Help Desk Operator role performs remote tasks on users and devices and can assign applications or policies. Scoped to the right groups it is exactly what a service desk needs. Unscoped, it is the ability to remotely act on every device in the organisation, granted to a third party.

A regulated firm asked who can wipe a device

The Admin permissions view answers that for a named account in seconds, and Roles by permission answers it the other way round, showing which assignments and groups grant a specific permission. Producing that evidence is considerably easier than reconstructing it from role names and group memberships during an examination.

An operator with site-based device populations

Devices at a plant, a yard or a remote facility often need local administrative support, and the person providing it should not be able to act on head office devices. Scope groups per site, with a scoped Help Desk Operator assignment, gives local capability without global reach.

An education institution using Intune for Education

The School Administrator role manages applications, settings and devices for its groups in Intune for Education, and can take remote actions including lock, restart and retire from management. Scoped per school or per campus, that delegates real capability while keeping the blast radius of a mistake local.

An organisation tightening privileged access generally

Multi Admin Approval now supports role-based access control, requiring a second administrator to approve changes to role permissions, admin groups or member group assignments. Combined with Privileged Identity Management elevation, that closes the loop where privileged access is both time bound and change controlled.

Three positions

How UAE organisations grant Intune administrative access.

The middle column is the overwhelming norm. A handful of people hold Intune Administrator or Global Administrator, everybody trusts each other, and there is no answer to who could wipe which devices.
Least privilege applied
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Helpdesk limited to their own devices
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Object visibility limited by scope tag
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Effective permissions answerable
Scoped roles and tagsYes
Everyone is an Intune AdministratorTrivially, everyone has all
Global Administrator for everythingTrivially, everyone has all
Role changes require approval
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Elevation is time bound
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Follows Microsoft published guidance
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingExplicitly not
Survives an audit question
Scoped roles and tagsYes
Everyone is an Intune AdministratorNo
Global Administrator for everythingNo
Blast radius of a compromised admin account
Scoped roles and tagsBounded
Everyone is an Intune AdministratorWhole estate
Global Administrator for everythingWhole tenant
Effort to set up
Scoped roles and tagsDays
Everyone is an Intune AdministratorNone
Global Administrator for everythingNone
Feature
Scoped roles and tags
Everyone is an Intune Administrator
Global Administrator for everything
Least privilege applied
YesNoNo
Helpdesk limited to their own devices
YesNoNo
Object visibility limited by scope tag
YesNoNo
Effective permissions answerable
YesTrivially, everyone has allTrivially, everyone has all
Role changes require approval
YesNoNo
Elevation is time bound
YesNoNo
Follows Microsoft published guidance
YesNoExplicitly not
Survives an audit question
YesNoNo
Blast radius of a compromised admin account
BoundedWhole estateWhole tenant
Effort to set up
DaysNoneNone
The built-in roles

Eleven roles, and the job each one is for.

Role descriptions as published. The Cloud PC roles appear only where the tenant has a Windows 365 subscription.
RoleWhat Microsoft says it does
Application ManagerManages mobile and managed applications, can read device information and view device configuration profiles
Endpoint Privilege ManagerManages Endpoint Privilege Management policies in the Intune console
Endpoint Privilege ReaderViews Endpoint Privilege Management policies in the Intune console
Endpoint Security ManagerManages security and compliance features such as security baselines, device compliance, Conditional Access and Defender for Endpoint
Help Desk OperatorPerforms remote tasks on users and devices, and can assign applications or policies to users or devices
Intune Role AdministratorManages custom roles and adds assignments for built-in roles. The only Intune role that can assign permissions to administrators
Policy and Profile ManagerManages compliance policy, configuration profiles, Apple enrolment, corporate device identifiers and security baselines
Read Only OperatorViews user, device, enrolment, configuration and application information, and cannot make changes
School AdministratorManages apps, settings and devices for their groups in Intune for Education, including remote lock, restart and retire
Cloud PC AdministratorRead and write access to all Cloud PC features in the Cloud PC area
Cloud PC ReaderRead access to all Cloud PC features in the Cloud PC area
Custom rolesAny combination of Intune permissions, for refined access supporting least privilege
How an engagement runs

Five steps, and the first one usually surprises somebody.

Typically three to six weeks. The technical work is straightforward. Agreeing which administrator should be able to do what, to whom, is the part that involves other people.
  1. 1

    Establish effective permissions as they are today

    Using the Admin permissions view per account rather than reading role names, because permissions are incremental across assignments and different scope tags across assignments can widen access further. We also list which Microsoft Entra roles currently reach Intune, since several do with varying permission levels.

  2. 2

    Map administrative jobs to the least privileged role

    Which people need to manage applications, which need endpoint security, which need policy and profile management, and which only need to read. Custom roles where a built-in role grants more than the job requires, which Microsoft explicitly supports for exactly that reason.

  3. 3

    Design scope groups and scope tags together

    Scope groups defining which users and devices each assignment can manage, deliberately not using add all users or add all devices. Scope tags defining which policies, applications and devices each assignment can see. Then a check that any exclude groups used in policy or application assignments are nested in or listed as scope groups.

  4. 4

    Move the broad roles into just-in-time elevation

    Global Administrator and Intune Administrator removed from standing assignment. Privileged Identity Management configured for the elevation path, choosing between the Entra role method that elevates in around ten seconds and the groups-based method that can take up to fifteen minutes, based on how the access is actually used.

  5. 5

    Turn on the governance and hand over the views

    Multi Admin Approval for role-based access control changes so a second administrator approves updates to permissions, admin groups or member assignments. Then the three monitoring views handed to whoever will answer permission questions, and role assignments added to the same review cycle as the rest of your access governance.

Straight answers

What organisations ask about Intune role-based access control.

Microsoft advises against it in unusually direct language: do not use the Global Administrator role in Intune, and it does not recommend using that role to administer or manage Intune. It acknowledges some features require it, naming certain mobile threat defence connectors, and says to use it only when necessary and remove it when the task is complete.

Also too broad for daily work. Microsoft describes it as granting global read and write permissions across Intune, classifies it as a privileged role, and states that while narrower than Global Administrator it still exceeds what is needed for almost all day-to-day management tasks. Its recommendation is to use a least-privileged built-in role or a custom role instead.

Scope groups define which users and devices an administrator with that role assignment can manage. Scope tags are freeform text values that limit the visibility of Intune objects such as policies, applications and devices to administrators whose role assignment carries a matching tag. One controls what you can act on, the other controls what you can see.

Almost always the incremental behaviour. Microsoft states permissions are incremental where two or more roles grant permissions to the same object, so read from one assignment plus read and write from another produces read and write. It also warns that where an administrator has multiple assignments using different scope tags, this can result in broader access than intended.

Microsoft has published an opt-in preview setting that changes how permissions apply so each role assignment permissions are contained to its own scope tag context, with documented steps to evaluate the impact on your tenant. It is worth assessing rather than enabling blindly, because the change affects what existing administrators can currently do.

Help Desk Operator, which Microsoft describes as performing remote tasks on users and devices and being able to assign applications or policies to users or devices. The important part is not the role, it is the scope. Assigned with scope groups covering only the devices that helpdesk supports, it is appropriate. Assigned unscoped, it reaches everything.

It depends when the account was created. Microsoft states that from June 2021 Intune began supporting unlicensed administrators, so user accounts created after that change can administer Intune without an assigned licence. Accounts created before that change, and administrator accounts in a nested security group assigned to a role, still require a licence.

By not granting it. Microsoft gives a specific instruction: when you configure a scope group, limit access by selecting only the security groups that include the users and devices that administrator should manage, and to ensure they cannot target all users or all devices, do not select add all users or add all devices. It is a single choice with a large consequence.

Check the scope. Microsoft states that if you specify an exclude group for an assignment such as a policy or application assignment, it needs to either be nested in one of the role assignment scope groups, or be separately listed as a scope group in the role assignment. Otherwise the exclusion does not apply, and the symptom looks nothing like a permissions problem.

Yes, through two supported methods with different characteristics. A Privileged Identity Management policy on the Entra Intune Administrator role, where elevation typically happens within 10 seconds. Or Privileged Identity Management for Groups with an Intune role assignment, which is better for least privilege but where elevation typically takes up to 15 minutes to apply.

Yes. Microsoft states Multi Admin Approval now supports role-based access control, so when the setting is on a second administrator must approve changes to roles, which can include updates to role permissions, admin groups or member group assignments, and the change takes effect only after approval. That is a strong control for the permission model itself.

The Admin permissions view. You specify a user account and, provided they have Intune permissions, Intune displays the complete list identified by permission and action. There are two companion views: My permissions for the signed-in user, and Roles by permission which works the other way round, showing which role assignments and groups grant a chosen permission.

Several, with different levels. Global Administrator and Intune Administrator have read and write on all Intune data. Security Administrator has read only, with full administrative permissions for the Endpoint Security node. Security Operator, Security Reader and Global Reader have read only. Helpdesk administrator, which Microsoft notes is equivalent to the Intune Help Desk Operator role, has read only. Conditional Access Administrator has none.

Often, and Microsoft supports them for exactly this reason: to grant administrators only the specific permissions needed for their tasks, supporting least privilege. Its own guidance is that if a least privileged built-in role still grants excessive permissions, consider a custom role to limit the scope. The Intune Role Administrator role is the only Intune role that can create and assign them.

We scope per organisation, driven by how many administrative populations exist and whether scope tags are being introduced across a multi-entity tenant. Three to six weeks is typical. The effective permissions review at the start is quick and it is usually what makes the case for the rest of the work.
The permissions review

Fifteen checks that reveal what your administrators can actually do.

The first group is who holds broad roles, the second is how assignments are scoped, and the third is the governance around changing any of it.

Who holds what

  • Who has Global Administrator?
    Microsoft says do not use it for Intune.
  • Who has Intune Administrator?
    Also too broad for daily tasks.
  • Which Entra roles reach Intune?
    Several do, with varying permissions.
  • Have you run the Admin permissions view?
    It shows effective permissions per account.
  • Does anybody hold multiple assignments?
    Permissions are incremental.

Scoping

  • Do any assignments use add all users?
    Microsoft advises against it.
  • Do any use add all devices?
    Same advice, same reason.
  • Are scope tags in use at all?
    Most tenants have none.
  • Do exclude groups sit inside scope groups?
    They must be nested or listed.
  • Are role assignment scopes documented?
    Otherwise nobody can explain them later.

Governance

  • Is Multi Admin Approval on for role changes?
    It now supports role-based access control.
  • Is PIM used for elevation?
    Two methods, with different timings.
  • Do administrators need licences?
    Depends when the account was created.
  • Are role assignments reviewed?
    They accumulate like every other permission.
  • Who can create role assignments?
    Only the Intune Role Administrator role.
Related reading

The pages around this one.

Privileged Identity Management

The elevation mechanism behind just-in-time Intune administration.

Learn more

Microsoft Intune

The product overview these permissions apply within.

Learn more

Entra access reviews

Recertifying the groups that role assignments are made to.

Learn more
Next step

Run the Admin permissions view on one helpdesk account. That is the whole assessment.

It shows the complete list of permissions that account actually holds, which is frequently broader than the person who granted it intended. Two minutes, one account, and it usually starts the conversation on its own.

Book an Intune permissions reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Privileged Identity Management

Just-in-time admin access, approval, and audit history you can download

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Entra Access Reviews

Recurring recertification of groups, apps and roles

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Intune Configuration Profiles

Settings catalog, templates and conflict management

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy