You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
*Applies to: Configuration Manager (current branch)*
19
19
20
20
Starting in Configuration Manager version 2207, you can use Intune role-based access control (RBAC) when interacting with [tenant attached devices](../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with the [Help Desk Operator role](../../intune/fundamentals/role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. [Intune role-based access control](../../intune/fundamentals/create-custom-role.md) manages the permissions to all cloud-attached device pages in the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com), such as [device timeline](../tenant-attach/timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), [CMPivot](../tenant-attach/cmpivot-start.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), and [scripts](../tenant-attach/scripts.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json).
@@ -31,7 +31,8 @@ The three high-level steps to configure Intune as the role-based access control
31
31
32
32
## Limitations
33
33
34
-
Currently [scoping](../../intune/fundamentals/scope-tags.md) isn't supported when using only Intune role-based access control for for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center.
34
+
- Currently [scoping](../../intune/fundamentals/scope-tags.md) isn't supported when using only Intune role-based access control for for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center.
35
+
- Currently, the [**Software updates** page](../tenant-attach/software-updates.md) isn't available for cloud-only users when using the early update ring of Configuration Manager version 2207. <!--15287859-->
35
36
36
37
## <aname="bkmk_disable-configmgr"></a> Disable enforcement of Configuration Manager role-based access control for cloud-attached clients
37
38
@@ -79,11 +80,11 @@ The following Intune permissions control access to the Configuration Manager clo
79
80
| Cloud attached devices\View timeline | Displays the **Timeline** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
80
81
| Cloud attached devices\View software updates | Displays the **Software updates** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Help Desk Operator |
81
82
| Cloud attached devices\View scripts | Displays the **Scripts** page for Configuration Manager cloud attached devices | Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
82
-
| Cloud attached devices\Run script | Displays the **Run script** action for Configuration Manager cloud attached devices | School Administrator, Help Desk Operator |
83
+
| Cloud attached devices\Run script | Displays the **Run script** action and allows the user to run scripts on Configuration Manager cloud attached devices | School Administrator, Help Desk Operator |
83
84
| Cloud attached devices\Run CMPivot query | Displays the **CMPivot** page for Configuration Manager cloud attached devices | Endpoint Security Manager, School Administrator, Help Desk Operator |
84
85
| Cloud attached devices\View client details | Displays the **Client details** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator,School Administrator, Policy Profile Manager, Help Desk Operator |
85
86
| Cloud attached devices\View applications | Displays the **Applications** page for Configuration Manager cloud attached devices | Application Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
86
-
| Cloud attached devices\Take application actions | Displays application actions in the **Applications** page for Configuration Manager cloud attached devices | Application Manager, School Administrator, Help Desk Operator |
87
+
| Cloud attached devices\Take application actions | Displays application actions in the **Applications** page and allows the user to take application actions on Configuration Manager cloud attached devices | Application Manager, School Administrator, Help Desk Operator |
87
88
| Remote tasks/Rotate BitLockerKeys (preview) | Initiates a key rotation for BitLocker Recovery Passwords on the device. Displays the *Recovery keys* page for Configuration Manager cloud attached devices. | Endpoint Security Manager, Help Desk Operator |
You can now use Intune role-based access control (RBAC) when interacting with tenant attached devices from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with Intune's [Help Desk Operator role](../../../../intune/fundamentals/role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. For more information, see [Intune role-based access control for tenant attached clients](../../../cloud-attach/use-intune-rbac.md).
32
+
28
33
### Enhanced security for Configuration Manager administration service
29
34
<!--12952905-->
30
35
We're introducing a new cloud application with limited access to the administration service. This feature allows cloud management gateway (CMG) to segment the admin privileges between a management point, and the administration service. This enables CMG to restrict access to the administration service. This feature gives admins granular access controls through which users can have access to the administration service and to enforce MFA if necessary.
Copy file name to clipboardExpand all lines: memdocs/configmgr/core/servers/deploy/install/release-notes.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Release notes
3
3
titleSuffix: Configuration Manager
4
4
description: Learn about urgent issues that aren't yet fixed in the product or covered in a Microsoft Support knowledge base article.
5
-
ms.date: 08/12/2022
5
+
ms.date: 08/24/2022
6
6
ms.prod: configuration-manager
7
7
ms.technology: configmgr-core
8
8
ms.topic: troubleshooting
@@ -183,11 +183,13 @@ For more information, see [Create custom security roles](../configure/configure-
183
183
184
184
## Configuration Manager console
185
185
186
-
### Intune RBAC for Tenant Attached devices
186
+
### Intune RBAC for tenant attached devices
187
187
<!--13058986-->
188
188
*Applies to: version 2207*
189
189
190
-
You'll now see a checkbox for a role-based access control (RBAC) setting in the cloud attach configuration wizard in the console. By default, Configuration Manager RBAC is enforced along with Intune RBAC when you're uploading your Configuration Manager devices to the cloud service. This checkbox is checked by default. If you want to enforce only Intune RBAC, you can uncheck the box. However, the enforcement of Intune RBAC only won't apply at this time. This release note and the [What's New in Intune](../../../../../intune/fundamentals/whats-new.md) will be updated when you're able to enforce Intune RBAC only. For more information, see, [Enable Microsoft Endpoint Manager tenant attach](../../../../../configmgr/tenant-attach/device-sync-actions.md)
190
+
***[Updated]***: There is a checkbox for a role-based access control (RBAC) setting in the [cloud attach configuration wizard](../../../../../cloud-attach/enable.md) in the console. By default, Configuration Manager RBAC is enforced along with Intune RBAC when you're uploading your Configuration Manager devices to the cloud service. This checkbox is selected by default.
191
+
192
+
You can now configure Intune role-based access control (RBAC) when interacting with [tenant attached devices](../../../../../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) from the Microsoft Endpoint Manager admin center. For more information, see [Intune role-based access control for tenant-attached clients](../../../../../cloud-attach/use-intune-rbac.md).
191
193
192
194
### Unable to open console because extension installation loops
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/whats-new.md
+10-1Lines changed: 10 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: Erikre
8
8
ms.author: erikre
9
9
manager: dougeby
10
-
ms.date: 08/15/2022
10
+
ms.date: 08/24/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: fundamentals
@@ -59,6 +59,15 @@ You can use RSS to be notified when this page is updated. For more information,
59
59
### Role-based access control
60
60
### Scripts
61
61
-->
62
+
63
+
## Week of August 22, 2022
64
+
65
+
### Device management
66
+
67
+
#### Use Intune role-based access control (RBAC) for tenant attached devices <!-- 14996522 -->
68
+
69
+
You can now use Intune role-based access control (RBAC) when interacting with tenant attached devices from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with Intune's [Help Desk Operator role](role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. For more information, see [Intune role-based access control for tenant attached clients](../../configmgr/cloud-attach/use-intune-rbac.md).
0 commit comments