Microsoft says do not use Global Administrator to manage Intune. Almost every tenant we look at does.
Intune has nine built-in roles, custom roles, scope groups that limit which devices an administrator can manage, and scope tags that limit which objects they can see. Used together they express least privilege properly. Used not at all, every Intune administrator can do everything to everyone.

- Nine built-in rolesPlus custom roles and Cloud PC roles
- Three partsMembers, scope groups and scope tags
- IncrementalMultiple assignments add permissions together
- 10s or 15 minPIM elevation timing, depending on method
Seven things that decide whether your Intune permissions mean anything.
Global Administrator is explicitly not the answer
Microsoft states it plainly: do not use the Global Administrator role in Intune, and it does not recommend using it to administer or manage Intune. Some features do require it, with mobile threat defence connectors given as an example, and the guidance there is to use it only when necessary and remove it when the task is complete.
Intune Administrator is also too much for daily work
Microsoft describes the Intune Administrator role as granting global read and write permissions across Intune, classified as a privileged role, and states that while its scope is narrower than Global Administrator it still exceeds what is needed for almost all day-to-day tasks. Its guidance is not to use it for routine administration. In Graph and PowerShell it appears as Intune Service Administrator.
Nine built-in roles, each for a real job
Application Manager, Endpoint Privilege Manager and Reader, Endpoint Security Manager, Help Desk Operator, Intune Role Administrator, Policy and Profile Manager, Read Only Operator and School Administrator. Where a Windows 365 subscription exists, Cloud PC Administrator and Cloud PC Reader appear as well. Most organisations need three or four of them and use none.
Scope groups limit which devices an administrator touches
Scope groups define the groups of users and devices an administrator with a role assignment can manage. Microsoft gives an explicit instruction here: to ensure administrators with a role cannot target all users or all devices, do not select add all users or add all devices. That single choice is the difference between a scoped helpdesk and an unscoped one.
Scope tags limit which objects an administrator can see
Freeform text values an administrator defines and adds to a role assignment. Microsoft distinguishes two effects: a scope tag on the role controls visibility of the role itself, while a scope tag in a role assignment limits visibility of Intune objects such as policies, applications and devices to administrators in assignments carrying a matching tag.
Three monitoring views, and nobody uses them
My permissions shows the effective permissions of the signed-in user. Roles by permission shows which role assignments and groups grant a specific permission. Admin permissions takes a named account and shows the complete list of permissions it currently holds. That last one answers the question an auditor asks, in about thirty seconds.
Just-in-time elevation, with two different timings
Two supported methods. A Privileged Identity Management policy on the Entra Intune Administrator role, where Microsoft states elevation typically happens within 10 seconds. Or Privileged Identity Management for Groups with an Intune role assignment, where elevation typically takes up to 15 minutes to apply. That difference matters when somebody is elevating during an incident.
Two role assignments with different scope tags can grant more than either was meant to.
Microsoft documents this directly, and it is the single most surprising thing about Intune role-based access control.
- Quoted: permissions are incremental where two or more roles grant permissions to the same object. A user with read from one role and read and write from another has an effective permission of read and write, assuming the assignments target the same scope tags.
- Quoted: when an administrator has multiple role assignments that use different scope tags, this behaviour can result in broader access than intended. That is not a defect, it is how the model composes, and it is not obvious from either assignment viewed alone.
- Microsoft has published an opt-in preview setting that changes how permissions apply so each role assignment permissions are contained to its own scope tag context, with steps to evaluate the impact on your tenant before enabling it.
- The practical implication is that reviewing role assignments individually tells you very little. The Admin permissions view, which shows the complete effective permission list for a named account, is the only reliable way to answer what somebody can actually do.
Four things that make an Intune permissions model hold.
We start from effective permissions, not from role names
The Admin permissions view takes a named account and shows the complete list of permissions it currently holds. Because permissions are incremental across assignments, and because different scope tags across assignments can widen access further than intended, reading the role names tells you what somebody was meant to have rather than what they have.
We scope by group and by tag, not by one or the other
Scope groups limit which users and devices an administrator can manage. Scope tags limit which policies, applications and devices they can see. They answer different questions and most organisations that attempt scoping use only the first. The instruction Microsoft gives is specific: do not select add all users or add all devices.
We get the broad Entra roles out of daily use
Microsoft says not to use Global Administrator for Intune, and not to use Intune Administrator for routine administration. Where a feature genuinely needs one, such as certain mobile threat defence connectors, the guidance is to elevate for the task and remove it afterwards. Privileged Identity Management makes that practical rather than aspirational.
We check the exclude group behaviour, which trips people up
Microsoft states that an exclude group used in a policy or application assignment needs to be either nested in one of the role assignment scope groups, or separately listed as a scope group in the role assignment. Get that wrong and exclusions silently fail to apply, which is a very hard problem to diagnose from the symptom.
Six UAE situations where Intune scoping stops being optional.
A group with several business units under one tenant
Scope groups and scope tags together let each unit administrator manage and see only their own devices and policies. Without them, an administrator in one subsidiary can view and modify configuration belonging to another, which becomes a governance question the first time somebody notices.
An organisation using an outsourced or offshore helpdesk
The Help Desk Operator role performs remote tasks on users and devices and can assign applications or policies. Scoped to the right groups it is exactly what a service desk needs. Unscoped, it is the ability to remotely act on every device in the organisation, granted to a third party.
A regulated firm asked who can wipe a device
The Admin permissions view answers that for a named account in seconds, and Roles by permission answers it the other way round, showing which assignments and groups grant a specific permission. Producing that evidence is considerably easier than reconstructing it from role names and group memberships during an examination.
An operator with site-based device populations
Devices at a plant, a yard or a remote facility often need local administrative support, and the person providing it should not be able to act on head office devices. Scope groups per site, with a scoped Help Desk Operator assignment, gives local capability without global reach.
An education institution using Intune for Education
The School Administrator role manages applications, settings and devices for its groups in Intune for Education, and can take remote actions including lock, restart and retire from management. Scoped per school or per campus, that delegates real capability while keeping the blast radius of a mistake local.
An organisation tightening privileged access generally
Multi Admin Approval now supports role-based access control, requiring a second administrator to approve changes to role permissions, admin groups or member group assignments. Combined with Privileged Identity Management elevation, that closes the loop where privileged access is both time bound and change controlled.
How UAE organisations grant Intune administrative access.
| Feature | Scoped roles and tags | Everyone is an Intune Administrator | Global Administrator for everything |
|---|---|---|---|
Least privilege applied | Yes | No | No |
Helpdesk limited to their own devices | Yes | No | No |
Object visibility limited by scope tag | Yes | No | No |
Effective permissions answerable | Yes | Trivially, everyone has all | Trivially, everyone has all |
Role changes require approval | Yes | No | No |
Elevation is time bound | Yes | No | No |
Follows Microsoft published guidance | Yes | No | Explicitly not |
Survives an audit question | Yes | No | No |
Blast radius of a compromised admin account | Bounded | Whole estate | Whole tenant |
Effort to set up | Days | None | None |
Eleven roles, and the job each one is for.
| Role | What Microsoft says it does | |
|---|---|---|
| Application Manager | Manages mobile and managed applications, can read device information and view device configuration profiles | |
| Endpoint Privilege Manager | Manages Endpoint Privilege Management policies in the Intune console | |
| Endpoint Privilege Reader | Views Endpoint Privilege Management policies in the Intune console | |
| Endpoint Security Manager | Manages security and compliance features such as security baselines, device compliance, Conditional Access and Defender for Endpoint | |
| Help Desk Operator | Performs remote tasks on users and devices, and can assign applications or policies to users or devices | |
| Intune Role Administrator | Manages custom roles and adds assignments for built-in roles. The only Intune role that can assign permissions to administrators | |
| Policy and Profile Manager | Manages compliance policy, configuration profiles, Apple enrolment, corporate device identifiers and security baselines | |
| Read Only Operator | Views user, device, enrolment, configuration and application information, and cannot make changes | |
| School Administrator | Manages apps, settings and devices for their groups in Intune for Education, including remote lock, restart and retire | |
| Cloud PC Administrator | Read and write access to all Cloud PC features in the Cloud PC area | |
| Cloud PC Reader | Read access to all Cloud PC features in the Cloud PC area | |
| Custom roles | Any combination of Intune permissions, for refined access supporting least privilege |
Five steps, and the first one usually surprises somebody.
- 1
Establish effective permissions as they are today
Using the Admin permissions view per account rather than reading role names, because permissions are incremental across assignments and different scope tags across assignments can widen access further. We also list which Microsoft Entra roles currently reach Intune, since several do with varying permission levels.
- 2
Map administrative jobs to the least privileged role
Which people need to manage applications, which need endpoint security, which need policy and profile management, and which only need to read. Custom roles where a built-in role grants more than the job requires, which Microsoft explicitly supports for exactly that reason.
- 3
Design scope groups and scope tags together
Scope groups defining which users and devices each assignment can manage, deliberately not using add all users or add all devices. Scope tags defining which policies, applications and devices each assignment can see. Then a check that any exclude groups used in policy or application assignments are nested in or listed as scope groups.
- 4
Move the broad roles into just-in-time elevation
Global Administrator and Intune Administrator removed from standing assignment. Privileged Identity Management configured for the elevation path, choosing between the Entra role method that elevates in around ten seconds and the groups-based method that can take up to fifteen minutes, based on how the access is actually used.
- 5
Turn on the governance and hand over the views
Multi Admin Approval for role-based access control changes so a second administrator approves updates to permissions, admin groups or member assignments. Then the three monitoring views handed to whoever will answer permission questions, and role assignments added to the same review cycle as the rest of your access governance.
What organisations ask about Intune role-based access control.
Fifteen checks that reveal what your administrators can actually do.
Who holds what
- Who has Global Administrator?Microsoft says do not use it for Intune.
- Who has Intune Administrator?Also too broad for daily tasks.
- Which Entra roles reach Intune?Several do, with varying permissions.
- Have you run the Admin permissions view?It shows effective permissions per account.
- Does anybody hold multiple assignments?Permissions are incremental.
Scoping
- Do any assignments use add all users?Microsoft advises against it.
- Do any use add all devices?Same advice, same reason.
- Are scope tags in use at all?Most tenants have none.
- Do exclude groups sit inside scope groups?They must be nested or listed.
- Are role assignment scopes documented?Otherwise nobody can explain them later.
Governance
- Is Multi Admin Approval on for role changes?It now supports role-based access control.
- Is PIM used for elevation?Two methods, with different timings.
- Do administrators need licences?Depends when the account was created.
- Are role assignments reviewed?They accumulate like every other permission.
- Who can create role assignments?Only the Intune Role Administrator role.
Run the Admin permissions view on one helpdesk account. That is the whole assessment.
It shows the complete list of permissions that account actually holds, which is frequently broader than the person who granted it intended. Two minutes, one account, and it usually starts the conversation on its own.
Related Services
Explore more solutions that work great with this service
Privileged Identity Management
Just-in-time admin access, approval, and audit history you can download
Microsoft Intune
Device management and endpoint security
Entra Access Reviews
Recurring recertification of groups, apps and roles
MDM Solutions Dubai
Device management across Windows, Apple and Android
Intune Configuration Profiles
Settings catalog, templates and conflict management
Access Rights Review
Certification that removes access, not one that gets approved
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
IT General Controls
What your external auditor tests, and the evidence they sample