|
| 1 | +--- |
| 2 | +title: Intune role-based access control for tenant-attached devices |
| 3 | +titleSuffix: Configuration Manager |
| 4 | +description: Enable Intune role-based access control for Configuration Manager tenant-attached clients |
| 5 | +ms.date: 08/24/2022 |
| 6 | +ms.prod: configuration-manager |
| 7 | +ms.technology: configmgr-core |
| 8 | +ms.topic: overview |
| 9 | +author: mestew |
| 10 | +ms.author: mstewart |
| 11 | +manager: dougeby |
| 12 | +ms.localizationpriority: high |
| 13 | +ms.collection: highpri |
| 14 | +--- |
| 15 | + |
| 16 | +# Intune role-based access control for tenant-attached clients |
| 17 | +<!--8126836, 6415648, 8348644, IN14996522, 13058986--> |
| 18 | +*Applies to: Configuration Manager (current branch)* |
| 19 | + |
| 20 | +Starting in Configuration Manager version 2207, you can use Intune role-based access control (RBAC) when interacting with [tenant attached devices](../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with the [Help Desk Operator role](../../intune/fundamentals/role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. [Intune role-based access control](../../intune/fundamentals/create-custom-role.md) manages the permissions to all cloud-attached device pages in the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com), such as [device timeline](../tenant-attach/timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), [CMPivot](../tenant-attach/cmpivot-start.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), and [scripts](../tenant-attach/scripts.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json). |
| 21 | + |
| 22 | +> [!IMPORTANT] |
| 23 | +> Currently, any enforcement of Intune role-based access control for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center is optional. We recommend all admins with cloud-connected Configuration Manager environments begin [verifying the role-based access control permissions from Intune](#bkmk_verify-intune-rbac). |
| 24 | +
|
| 25 | +The three high-level steps to configure Intune as the role-based access control authority for tenant-attached devices are: |
| 26 | +<!--To enable Intune role-based access control as the authority, the following high-level steps --> |
| 27 | + |
| 28 | +- From the Configuration Manager console, [disable enforcement of Configuration Manager role-based access control](#bkmk_disable-configmgr) for cloud-attached clients |
| 29 | +- From Intune, [enable managing the user permissions](#bkmk_enable-intune) for cloud-attached devices |
| 30 | +- From Intune, [verify role-based access control permissions](#bkmk_verify-intune-rbac) for cloud-attached devices |
| 31 | + |
| 32 | +## Prerequisites |
| 33 | + |
| 34 | +- Configuration Manager version 2207 or later |
| 35 | +- [Tenant attached devices](../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) |
| 36 | + |
| 37 | +## Limitations |
| 38 | + |
| 39 | +- Currently [scoping](../../intune/fundamentals/scope-tags.md) isn't supported when using only Intune role-based access control for for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center. |
| 40 | +- Currently, the [**Software updates** page](../tenant-attach/software-updates.md) isn't available for cloud-only users when using the early update ring of Configuration Manager version 2207. <!--15287859--> |
| 41 | + |
| 42 | +## <a name="bkmk_disable-configmgr"></a> Disable enforcement of Configuration Manager role-based access control for cloud-attached clients |
| 43 | + |
| 44 | +To use Intune role-based access control for tenant attach rather than Configuration Manager role-based access control, use the instructions below: |
| 45 | + |
| 46 | +1. From the Configuration Manager console, go to, **Administration** > **Cloud Services** > **Cloud Attach**. |
| 47 | +1. The location of the role-based access control option varies depending on if your environment is already cloud-attached or not. |
| 48 | + - If your environment is already cloud-attached, open the properties for **CoMgmtSettingsProd**. If you don't have devices uploaded to the admin center, configure that option first. For more information, see [Enable cloud attach](enable.md). |
| 49 | + - If your environment isn't cloud-attached, select **Configure Cloud Attach** to open the **Cloud Attach Configuration wizard**. |
| 50 | +1. On the **Configure upload** tab, or page in the wizard, clear the checkbox for the following option under the **Role-based Access Control** heading: |
| 51 | + |
| 52 | + **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** |
| 53 | + |
| 54 | +1. Choose **OK** to save the change to the **CoMgmtSettingsProd** properties, or continue on to complete the [cloud attach wizard](enable.md). |
| 55 | + |
| 56 | +:::image type="content" source="media/14996522-configure-upload.png" alt-text="Screenshot of the CoMgmtSettingsProd properties in Configuration Manager. In the screenshot, the configure upload tab is displayed with a red box outlining the role-based access control section." lightbox="media/14996522-configure-upload.png"::: |
| 57 | + |
| 58 | +## <a name="bkmk_enable-intune"></a> Enable role-based access control from Intune |
| 59 | + |
| 60 | +To enable Intune to manage user permissions for cloud-attached devices, use the following steps: |
| 61 | + |
| 62 | +1. Open the [Microsoft Endpoint admin center](https://endpoint.microsoft.com) and sign in. |
| 63 | +1. Select **Tenant administration** > **Connectors and tokens** > **Microsoft Endpoint Configuration Manager**. |
| 64 | +1. In the banner, select **You can also manage user permissions from Intune. Click here to learn more about this option.** |
| 65 | +1. The **Use Intune RBAC** flyout appears. |
| 66 | +1. Select **On** for the **Use Intune RBAC** option, then choose **Apply**. |
| 67 | +1. The change may take about 10 minutes to take effect. |
| 68 | + |
| 69 | +:::image type="content" source="media/14996522-connectors-flyout.png" alt-text="Screenshot of the Microsoft Endpoint Configuration Manager connectors and tokens page in Microsoft Endpoint Manager admin center. The Use Intune RBAC flyout is displayed in the screenshot." lightbox="media/14996522-connectors-flyout.png"::: |
| 70 | + |
| 71 | +## <a name="bkmk_verify-intune-rbac"></a> Verify role-based access control permissions from Intune |
| 72 | + |
| 73 | +Once Intune is set to the role-based access control authority, verify the permissions for your roles. If needed, you can add these permissions to [custom roles](../../intune/fundamentals/create-custom-role.md) you created in Intune. |
| 74 | + |
| 75 | +1. Open the [Microsoft Endpoint admin center](https://endpoint.microsoft.com) and sign in. |
| 76 | +1. Select **Tenant administration** > **Roles**. |
| 77 | +1. Select a role, such as **Application Manager**, and review the permissions listed for **Cloud attached devices**. If needed, edit permissions for any [custom roles](../../intune/fundamentals/create-custom-role.md) you created in Intune. |
| 78 | + |
| 79 | +The following Intune permissions control access to the Configuration Manager cloud-attached devices: |
| 80 | + |
| 81 | +| Permission | Description | Intune built-in roles with the permission | |
| 82 | +|---|---|---| |
| 83 | +| Cloud attached devices\View collections | Displays the **Collections** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator | |
| 84 | +| Cloud attached devices\View resource explorer | Displays the **Resource explorer** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator | |
| 85 | +| Cloud attached devices\View timeline | Displays the **Timeline** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator | |
| 86 | +| Cloud attached devices\View software updates | Displays the **Software updates** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Help Desk Operator | |
| 87 | +| Cloud attached devices\View scripts | Displays the **Scripts** page for Configuration Manager cloud attached devices | Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator | |
| 88 | +| Cloud attached devices\Run script | Displays the **Run script** action and allows the user to run scripts on Configuration Manager cloud attached devices | School Administrator, Help Desk Operator | |
| 89 | +| Cloud attached devices\Run CMPivot query | Displays the **CMPivot** page for Configuration Manager cloud attached devices | Endpoint Security Manager, School Administrator, Help Desk Operator | |
| 90 | +| Cloud attached devices\View client details | Displays the **Client details** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator,School Administrator, Policy Profile Manager, Help Desk Operator | |
| 91 | +| Cloud attached devices\View applications | Displays the **Applications** page for Configuration Manager cloud attached devices | Application Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator | |
| 92 | +| Cloud attached devices\Take application actions | Displays application actions in the **Applications** page and allows the user to take application actions on Configuration Manager cloud attached devices | Application Manager, School Administrator, Help Desk Operator | |
| 93 | +| Remote tasks/Rotate BitLockerKeys (preview) | Initiates a key rotation for BitLocker Recovery Passwords on the device. Displays the *Recovery keys* page for Configuration Manager cloud attached devices. | Endpoint Security Manager, Help Desk Operator | |
| 94 | + |
| 95 | +## <a name="bkmk_faq"></a> Frequently asked questions |
| 96 | + |
| 97 | +### I have cloud-only users that need access to tenant-attached devices in Intune, will this give them access? |
| 98 | + |
| 99 | +Yes. When a user is cloud only, in this scenario meaning they are in Azure Active Directory (Azure AD) and can access Intune, using Intune RBAC will give them access to tenant-attached devices. |
| 100 | + |
| 101 | +### What if I have multiple Configuration Manager hierarchies connected to my tenant? |
| 102 | + |
| 103 | +The **Use Intune RBAC** setting in the Microsoft Endpoint Manager admin center applies to all of the Configuration Manager hierarchies listed in the tenant. |
| 104 | + |
| 105 | +### What happens if the Configuration Manager and Intune settings are mismatched? |
| 106 | + |
| 107 | +If the **Use Intune RBAC** toggle in Intune is set to **Off**, then Configuration Manager role-based access will be enforced, even if the **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** checkbox is cleared. Disabling the **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** option doesn't have any effect until the **Use Intune RBAC** toggle in Intune is set to **On**. |
| 108 | + |
| 109 | +### What happens if my test hierarchy is configured to use Intune RBAC, but my production hierarchy isn't and they are in the same tenant? |
| 110 | + |
| 111 | +The **Use Intune RBAC** setting applies to all of the Configuration Manager hierarchies listed in the tenant. Cloud-only users can access tenant-attached devices that are uploaded from the test hierarchy because you've also cleared the checkbox to enforce Configuration Manager RBAC. If a cloud-only user tries to access a tenant-attached device uploaded from the production environment, they'll receive an error since production devices are enforcing Configuration Manager RBAC. The cloud-only user will receive an error similar to the following message: |
| 112 | +`Unable to get device information. Make sure Azure AD and AD user discovery are configured and the user is discovered by both. Verify that the user has proper permissions in Configuration Manager.` |
| 113 | + |
| 114 | + |
| 115 | +## Next steps |
| 116 | + |
| 117 | +- Review the [timeline](../tenant-attach/timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) for a cloud-attached device |
| 118 | +- Run a [CMPivot](../tenant-attach/cmpivot-start.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) query on a cloud attached device |
0 commit comments