Skip to content

Commit b8ee799

Browse files
authored
Merge pull request #8235 from mestew/inado-14996522-rbac
Publish 8/25 around 8 AM - [hold 8/23ish] Inado 14996522 rbac
2 parents 13c8486 + 97dc578 commit b8ee799

13 files changed

Lines changed: 316 additions & 164 deletions

File tree

memdocs/configmgr/cloud-attach/enable.md

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Enable cloud attach
33
titleSuffix: Configuration Manager
44
description: Enable cloud attach for Configuration Manager
5-
ms.date: 12/01/2021
5+
ms.date: 08/15/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-core
88
ms.topic: overview
@@ -75,11 +75,16 @@ Use the following steps to cloud attach your environment with custom settings:
7575
**Select which devices to upload to Microsoft Endpoint Manager** has the following two options:
7676
- **All devices managed my Microsoft Endpoint Configuration Manager (recommended)**: Upload all devices
7777
- **Specific Collection**: Upload a specific collection, including any subcollections.
78-
79-
1. The **Endpoint Analytics** section of the **Configure Upload** page, enables Enables [Endpoint analytics](../../analytics/scores.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) for devices uploaded to Microsoft Endpoint Manager. Endpoint analytics reports focus on the quality of the experience you're delivering to your users and helps you identify issues to proactively make improvements.
78+
1. The **Endpoint Analytics** section of the **Configure Upload** page, enables [Endpoint analytics](../../analytics/scores.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) for devices uploaded to Microsoft Endpoint Manager. Endpoint analytics reports focus on the quality of the experience you're delivering to your users and helps you identify issues to proactively make improvements.
8079

8180
Ensure the **Enable Endpoint Analytics for devices uploaded to Microsoft Endpoint Manager** option is selected to enable Endpoint Analytics.
8281

82+
1. In the **Role-based access control** section of the **Configure Upload** page, determine if you need to clear the checkbox for the **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** option. (*Introduced in version 2207*)
83+
- This option is used for setting Intune as the role-based access control authority for tenant-attached clients. For more information about configuring this option, see [Intune role-based access control for tenant-attached clients](use-intune-rbac.md).
84+
85+
> [!IMPORTANT]
86+
> When this checkbox is cleared, [settings in Intune need to be configured](use-intune-rbac.md) too.
87+
8388
1. Select **Next** to get to the **Enablement** page for [co-management](../comanage/tutorial-co-manage-clients.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json). Co-management simplifies management by enrolling devices into Intune and allowing you to lift selected [workloads](../comanage/workloads.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) to the cloud. For instance, you can choose to enable workloads for [Conditional Access](../comanage/quickstart-conditional-access.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) so only trusted users can access organizational resources on trusted devices using trusted apps.
8489

8590
Choose your co-management setting from the following options under **Automatic enrollment in Intune**:
227 KB
Loading
244 KB
Loading

memdocs/configmgr/cloud-attach/toc.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,16 @@ items:
33
href: index.yml
44
- name: What is cloud attach?
55
href: overview.md
6-
- name: Enable cloud attach
6+
- name: Enable cloud attach, versions 2111 and later
77
href: enable.md
88
- name: Tenant attach
99
items:
1010
- name: Tenant attach prerequisites
1111
href: ../tenant-attach/prerequisites.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
12-
- name: Enable tenant attach
12+
- name: Enable tenant attach, versions 2103 and earlier
1313
href: ../tenant-attach/device-sync-actions.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
14+
- name: Use Intune RBAC for tenant attach
15+
href: use-intune-rbac.md
1416
- name: Use tenant attach
1517
items:
1618
- name: Client details
@@ -71,7 +73,7 @@ items:
7173
href: ../tenant-attach/troubleshoot-applications.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
7274
- name: Common error codes for application installation
7375
href: ../tenant-attach/app-install-error-reference.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
74-
- name: ../tenant-attach/Timeline
76+
- name: Timeline
7577
href: ../tenant-attach/troubleshoot-timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
7678
- name: Resource explorer
7779
href: ../tenant-attach/troubleshoot-resource-explorer.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
Lines changed: 118 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,118 @@
1+
---
2+
title: Intune role-based access control for tenant-attached devices
3+
titleSuffix: Configuration Manager
4+
description: Enable Intune role-based access control for Configuration Manager tenant-attached clients
5+
ms.date: 08/24/2022
6+
ms.prod: configuration-manager
7+
ms.technology: configmgr-core
8+
ms.topic: overview
9+
author: mestew
10+
ms.author: mstewart
11+
manager: dougeby
12+
ms.localizationpriority: high
13+
ms.collection: highpri
14+
---
15+
16+
# Intune role-based access control for tenant-attached clients
17+
<!--8126836, 6415648, 8348644, IN14996522, 13058986-->
18+
*Applies to: Configuration Manager (current branch)*
19+
20+
Starting in Configuration Manager version 2207, you can use Intune role-based access control (RBAC) when interacting with [tenant attached devices](../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with the [Help Desk Operator role](../../intune/fundamentals/role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. [Intune role-based access control](../../intune/fundamentals/create-custom-role.md) manages the permissions to all cloud-attached device pages in the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com), such as [device timeline](../tenant-attach/timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), [CMPivot](../tenant-attach/cmpivot-start.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json), and [scripts](../tenant-attach/scripts.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json).
21+
22+
> [!IMPORTANT]
23+
> Currently, any enforcement of Intune role-based access control for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center is optional. We recommend all admins with cloud-connected Configuration Manager environments begin [verifying the role-based access control permissions from Intune](#bkmk_verify-intune-rbac).
24+
25+
The three high-level steps to configure Intune as the role-based access control authority for tenant-attached devices are:
26+
<!--To enable Intune role-based access control as the authority, the following high-level steps -->
27+
28+
- From the Configuration Manager console, [disable enforcement of Configuration Manager role-based access control](#bkmk_disable-configmgr) for cloud-attached clients
29+
- From Intune, [enable managing the user permissions](#bkmk_enable-intune) for cloud-attached devices
30+
- From Intune, [verify role-based access control permissions](#bkmk_verify-intune-rbac) for cloud-attached devices
31+
32+
## Prerequisites
33+
34+
- Configuration Manager version 2207 or later
35+
- [Tenant attached devices](../tenant-attach/client-details.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json)
36+
37+
## Limitations
38+
39+
- Currently [scoping](../../intune/fundamentals/scope-tags.md) isn't supported when using only Intune role-based access control for for displaying and taking actions on tenant-attached devices from the Microsoft Endpoint Manager admin center.
40+
- Currently, the [**Software updates** page](../tenant-attach/software-updates.md) isn't available for cloud-only users when using the early update ring of Configuration Manager version 2207. <!--15287859-->
41+
42+
## <a name="bkmk_disable-configmgr"></a> Disable enforcement of Configuration Manager role-based access control for cloud-attached clients
43+
44+
To use Intune role-based access control for tenant attach rather than Configuration Manager role-based access control, use the instructions below:
45+
46+
1. From the Configuration Manager console, go to, **Administration** > **Cloud Services** > **Cloud Attach**.
47+
1. The location of the role-based access control option varies depending on if your environment is already cloud-attached or not.
48+
- If your environment is already cloud-attached, open the properties for **CoMgmtSettingsProd**. If you don't have devices uploaded to the admin center, configure that option first. For more information, see [Enable cloud attach](enable.md).
49+
- If your environment isn't cloud-attached, select **Configure Cloud Attach** to open the **Cloud Attach Configuration wizard**.
50+
1. On the **Configure upload** tab, or page in the wizard, clear the checkbox for the following option under the **Role-based Access Control** heading:
51+
52+
**Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager**
53+
54+
1. Choose **OK** to save the change to the **CoMgmtSettingsProd** properties, or continue on to complete the [cloud attach wizard](enable.md).
55+
56+
:::image type="content" source="media/14996522-configure-upload.png" alt-text="Screenshot of the CoMgmtSettingsProd properties in Configuration Manager. In the screenshot, the configure upload tab is displayed with a red box outlining the role-based access control section." lightbox="media/14996522-configure-upload.png":::
57+
58+
## <a name="bkmk_enable-intune"></a> Enable role-based access control from Intune
59+
60+
To enable Intune to manage user permissions for cloud-attached devices, use the following steps:
61+
62+
1. Open the [Microsoft Endpoint admin center](https://endpoint.microsoft.com) and sign in.
63+
1. Select **Tenant administration** > **Connectors and tokens** > **Microsoft Endpoint Configuration Manager**.
64+
1. In the banner, select **You can also manage user permissions from Intune. Click here to learn more about this option.**
65+
1. The **Use Intune RBAC** flyout appears.
66+
1. Select **On** for the **Use Intune RBAC** option, then choose **Apply**.
67+
1. The change may take about 10 minutes to take effect.
68+
69+
:::image type="content" source="media/14996522-connectors-flyout.png" alt-text="Screenshot of the Microsoft Endpoint Configuration Manager connectors and tokens page in Microsoft Endpoint Manager admin center. The Use Intune RBAC flyout is displayed in the screenshot." lightbox="media/14996522-connectors-flyout.png":::
70+
71+
## <a name="bkmk_verify-intune-rbac"></a> Verify role-based access control permissions from Intune
72+
73+
Once Intune is set to the role-based access control authority, verify the permissions for your roles. If needed, you can add these permissions to [custom roles](../../intune/fundamentals/create-custom-role.md) you created in Intune.
74+
75+
1. Open the [Microsoft Endpoint admin center](https://endpoint.microsoft.com) and sign in.
76+
1. Select **Tenant administration** > **Roles**.
77+
1. Select a role, such as **Application Manager**, and review the permissions listed for **Cloud attached devices**. If needed, edit permissions for any [custom roles](../../intune/fundamentals/create-custom-role.md) you created in Intune.
78+
79+
The following Intune permissions control access to the Configuration Manager cloud-attached devices:
80+
81+
| Permission | Description | Intune built-in roles with the permission |
82+
|---|---|---|
83+
| Cloud attached devices\View collections | Displays the **Collections** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
84+
| Cloud attached devices\View resource explorer | Displays the **Resource explorer** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
85+
| Cloud attached devices\View timeline | Displays the **Timeline** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
86+
| Cloud attached devices\View software updates | Displays the **Software updates** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator, School Administrator, Help Desk Operator |
87+
| Cloud attached devices\View scripts | Displays the **Scripts** page for Configuration Manager cloud attached devices | Endpoint Security Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
88+
| Cloud attached devices\Run script | Displays the **Run script** action and allows the user to run scripts on Configuration Manager cloud attached devices | School Administrator, Help Desk Operator |
89+
| Cloud attached devices\Run CMPivot query | Displays the **CMPivot** page for Configuration Manager cloud attached devices | Endpoint Security Manager, School Administrator, Help Desk Operator |
90+
| Cloud attached devices\View client details | Displays the **Client details** page for Configuration Manager cloud attached devices | Application Manager, Endpoint Security Manager, Read Only Operator,School Administrator, Policy Profile Manager, Help Desk Operator |
91+
| Cloud attached devices\View applications | Displays the **Applications** page for Configuration Manager cloud attached devices | Application Manager, Read Only Operator, School Administrator, Policy Profile Manager, Help Desk Operator |
92+
| Cloud attached devices\Take application actions | Displays application actions in the **Applications** page and allows the user to take application actions on Configuration Manager cloud attached devices | Application Manager, School Administrator, Help Desk Operator |
93+
| Remote tasks/Rotate BitLockerKeys (preview) | Initiates a key rotation for BitLocker Recovery Passwords on the device. Displays the *Recovery keys* page for Configuration Manager cloud attached devices. | Endpoint Security Manager, Help Desk Operator |
94+
95+
## <a name="bkmk_faq"></a> Frequently asked questions
96+
97+
### I have cloud-only users that need access to tenant-attached devices in Intune, will this give them access?
98+
99+
Yes. When a user is cloud only, in this scenario meaning they are in Azure Active Directory (Azure AD) and can access Intune, using Intune RBAC will give them access to tenant-attached devices.
100+
101+
### What if I have multiple Configuration Manager hierarchies connected to my tenant?
102+
103+
The **Use Intune RBAC** setting in the Microsoft Endpoint Manager admin center applies to all of the Configuration Manager hierarchies listed in the tenant.
104+
105+
### What happens if the Configuration Manager and Intune settings are mismatched?
106+
107+
If the **Use Intune RBAC** toggle in Intune is set to **Off**, then Configuration Manager role-based access will be enforced, even if the **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** checkbox is cleared. Disabling the **Enforce Configuration Manager RBAC for cloud console requests that interact with Configuration Manager** option doesn't have any effect until the **Use Intune RBAC** toggle in Intune is set to **On**.
108+
109+
### What happens if my test hierarchy is configured to use Intune RBAC, but my production hierarchy isn't and they are in the same tenant?
110+
111+
The **Use Intune RBAC** setting applies to all of the Configuration Manager hierarchies listed in the tenant. Cloud-only users can access tenant-attached devices that are uploaded from the test hierarchy because you've also cleared the checkbox to enforce Configuration Manager RBAC. If a cloud-only user tries to access a tenant-attached device uploaded from the production environment, they'll receive an error since production devices are enforcing Configuration Manager RBAC. The cloud-only user will receive an error similar to the following message:
112+
`Unable to get device information. Make sure Azure AD and AD user discovery are configured and the user is discovered by both. Verify that the user has proper permissions in Configuration Manager.`
113+
114+
115+
## Next steps
116+
117+
- Review the [timeline](../tenant-attach/timeline.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) for a cloud-attached device
118+
- Run a [CMPivot](../tenant-attach/cmpivot-start.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json) query on a cloud attached device

memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2207.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: What's new in version 2207
33
titleSuffix: Configuration Manager
44
description: Get details about changes and new capabilities introduced in version 2207 of Configuration Manager current branch.
5-
ms.date: 08/12/2022
5+
ms.date: 08/24/2022
66
ms.prod: configuration-manager
77
ms.technology: configmgr-core
88
ms.topic: conceptual
@@ -25,6 +25,11 @@ To take full advantage of new Configuration Manager features, after you update t
2525

2626
## Cloud-attached management
2727

28+
### Use Intune role-based access control (RBAC) for tenant attached devices
29+
<!--8126836, 6415648, 8348644, IN14996522, 13058986-->
30+
31+
You can now use Intune role-based access control (RBAC) when interacting with tenant attached devices from the Microsoft Endpoint Manager admin center. For example, when using Intune as the role-based access control authority, a user with Intune's [Help Desk Operator role](../../../../intune/fundamentals/role-based-access-control.md#built-in-roles) doesn't need an assigned security role or additional permissions from Configuration Manager. For more information, see [Intune role-based access control for tenant attached clients](../../../cloud-attach/use-intune-rbac.md).
32+
2833
### Enhanced security for Configuration Manager administration service
2934
<!--12952905-->
3035
We're introducing a new cloud application with limited access to the administration service. This feature allows cloud management gateway (CMG) to segment the admin privileges between a management point, and the administration service. This enables CMG to restrict access to the administration service. This feature gives admins granular access controls through which users can have access to the administration service and to enforce MFA if necessary.

0 commit comments

Comments
 (0)