Intune – Additional permissions for the Endpoint Security Manager role

As you know, you can delegate permissions to allow certain administrative or management tasks using RBAC (Role Based Access Control) on Intune/Endpoint Configuration Manager.

Well, new permissions have been added to the Endpoint Security Manager role:

  • Initiate Configuration Manager action
  • Microsoft Defender ATP
  • Reboot now
  • Remote lock
  • Rotate BitLockerKeys (preview)
  • Rotate FileVault key
  • Shut down
  • Sync devices

If you are using the built-in Endpoint Security Manager role, you have nothing to do, except maybe some communication to the delegates.

If you are using custom role to delegate permissions, you may have to update your custom role to reflect these new permissions.

image_thumb

Intune – Migrate your Windows Defender Firewall GPO’s rules for use with Intune/Endpoint Configuration Manager

As you know, you can manage and configure your Windows Defender Firewall with Intune/Endpoint Configuration Manager, including rules.

Read More

Intune – you can now get details about devices in co-management configuration

As you know, you can have System Center Configuration Manager (SCCM)/Endpoint Configuration Manager (on-premises) working in some sort of hybrid...

Read More

Office 365 / Intune – Intune roles management is now integrated with the Office 365 administration portal

If you are using Office 365 and Intune/Endpoint Configuration Manager, you already know you had to manage administration roles from 2 different...

Read More