IntuneHow-to

Intune RBAC and scope tags: delegate administration without Intune Administrator

How Intune roles, role assignments and scope tags fit together, three delegation designs that work, the pitfalls that leak visibility, and how to audit and test what an admin can really do.

Most tenants start with a handful of people holding the Microsoft Entra Intune Administrator role, and that is fine until the helpdesk, a regional IT team and the packaging team all need access too. Intune role-based access control (RBAC) lets you give each group exactly the permissions and the visibility it needs. In this post I'll explain how roles, assignments and scope tags work together, walk through three common delegation designs, and show how to audit and verify the result.

How this guide is organised: How it works → Step-by-step → Common delegation designs → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (4 steps: Pick a role, or build one; Create scope tags; Create the role assignment; Tag the objects). 3. Common delegation designs. 4. Verify. 5. Tips & gotchas. Toolbox: Roles › All roles, Assignments › Assign, auditEvents, Roles › Monitor, Reports › Diagnostics settings.1How it works2Step-by-step3Commondelegation de…4Verify5Tips & gotchas1Pick a role, or build one2Create scope tags3Create the roleassignment4Tag the objectsTOOLBOXRoles › All rolesAssignments › AssignauditEventsRoles › MonitorReports › Diagnostics settingsHow this guide is organised: How it works → Step-by-step → Common delegation designs → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (4 steps: Pick a role, or build one; Create scope tags; Create the role assignment; Tag the objects). 3. Common delegation designs. 4. Verify. 5. Tips & gotchas. Toolbox: Roles › All roles, Assignments › Assign, auditEvents, Roles › Monitor, Reports › Diagnostics settings.1How it works2Step-by-step1Pick a role, or build one2Create scope tags3Create the role assignment4Tag the objects3Common delegation designs4Verify5Tips & gotchasTOOLBOXRoles › All rolesAssignments › AssignauditEventsRoles › MonitorReports › Diagnostics settings
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

How it works#

Intune RBAC has three moving parts, and confusing them is the root of most delegation problems:

  • Roles define what an admin can do. Permissions are grouped by category (Mobile apps, Device configurations, Remote tasks, Audit data and so on) with actions such as Read, Create, Update, Delete and Assign. Built-in roles are identical in every tenant and can't be edited; custom roles can contain any combination of permissions.
  • Role assignments connect a role to people. Each assignment has Members (the Microsoft Entra security groups whose users receive the role), Scope (Groups) (the user and device groups those admins are allowed to manage and target) and Scope (Tags).
  • Scope tags define which objects an admin can see. An admin only sees policies, apps, devices and other objects that carry at least one tag matching their role assignment. Tags are free-form labels you create under Tenant administration › Roles › Scope (Tags).

Two details about the Default scope tag matter a lot. First, Intune adds it automatically to every untagged object that supports tags, so "untagged" really means "tagged Default". Second, an admin whose role assignment has no scope tags effectively has all tags and sees everything their permissions allow. Scope tags only start filtering once you add them to the assignment.

Remember also that Intune RBAC doesn't restrict Microsoft Entra roles: Global Administrator and Intune Administrator keep full access regardless of tags. Microsoft recommends keeping those roles for the rare tasks that require them and using Intune roles for day-to-day work.

Step-by-step#

Step 1: Pick a role, or build one#

Review the built-in roles under Tenant administration › Roles › All roles. The ones you'll use most are Help Desk Operator (remote tasks, assigning apps and policies), Policy and Profile Manager, Application Manager, Endpoint Security Manager and Read Only Operator. Intune Role Administrator is the only Intune role that can create role assignments. If no built-in role fits, select Create for a custom role, or tick an existing role and choose Duplicate to copy its permissions and trim them. Creating or editing roles requires the Microsoft Entra Intune Administrator role, and if Multi Admin Approval is enabled for RBAC, a second admin has to approve the change.

Step 2: Create scope tags#

Go to Tenant administration › Roles › Scope (Tags) › Create. Name the tag after the boundary it represents (a region, a business unit, a device class). On the Assignments page you can select device groups whose members automatically receive the tag. Note that these automatic assignments overwrite manually assigned tags, and a device in several tagged groups receives all of those tags.

Step 3: Create the role assignment#

Open the role, select Assignments › Assign, and fill in the three pages: Admin Groups (members), Scope Groups (prefer specific groups over Add all users or Add all devices) and Scope tags. A role assignment and an object can each carry up to 100 tags.

Step 4: Tag the objects#

For most objects, scope tags live under Properties › Scope (Tags) › Edit. Two shortcuts help here: when a scoped admin creates an object, Intune stamps it with that admin's tags automatically, and apps bought through Apple Volume Purchase Program inherit the tags of their token. A few object types don't support tags at all: corporate device identifiers, Windows Autopilot devices, device compliance locations and Jamf devices.

Common delegation designs#

TeamRoleScope (Groups)Scope (Tags)Why it works
HelpdeskHelp Desk Operator, or a custom role with Managed devices Read plus the Remote tasks you allow (Sync devices, Reboot now, Remote lock, Collect diagnostics)All users and all devices, or the regions they supportDefault plus any regional tagsThey can act on devices but can't create or change policy
Regional adminsPolicy and Profile Manager (often also Application Manager)Groups containing that region's users and devicesThe regional tag onlyThey see and manage only objects tagged for their region; new objects they create are tagged automatically
App packagersApplication Manager, or a custom role with Mobile apps Create/Read/Update/Delete/Relate but no AssignA pilot group, so they can only target test devicesAn "Apps" tagThey build and test packages; production assignment stays with the platform team

Tip: If a regional admin must manage exclusion groups, each excluded group has to be nested inside one of the assignment's scope groups or listed as a scope group itself. Otherwise the exclusion can't be created.

Verify#

Don't guess what an admin can do; check it. Under Tenant administration › Roles › Monitor you'll find three views: My permissions (your own effective permissions), Roles by permission (pick a permission and action to see which assignments and groups grant it) and Admin permissions (enter a user and see everything they hold). Then sign in with a test account that is a member of the admin group and confirm:

  1. Only the expected policies, apps and devices appear in the lists.
  2. Creating a test profile stamps it with the right scope tag automatically.
  3. Assigning it offers only groups within the Scope (Groups).
  4. Actions outside the role (for example, deleting a device) are missing or denied.

Every create, update, delete, assign and remote action lands in Tenant administration › Audit logs. Filter by Category (there is a dedicated Role category) and Activity, or export the list to CSV. Audit data can also be routed to Azure Monitor from Reports › Diagnostics settings, and the Graph auditEvents API returns up to two years of history. Reading audit logs requires the Audit data Read permission or the Intune Administrator role.

Tips & gotchas#

  • Untagged objects are the usual leak. Anything without a tag carries Default, and any assignment that includes Default sees it all. Keep Default for the central team only, and tag everything you delegate.
  • Groups are not tags. Scope (Groups) limits who an admin can target; Scope (Tags) limits what they can see. A regional admin with the right tags but the wrong scope groups will see their policies and be unable to assign them, and vice versa.
  • Multiple assignments add up. By default, when an admin holds several assignments in the same permission category, Intune merges the permissions across all their tags, which can grant more than you intended. In March 2026 Intune added an opt-in Scoped permissions preview under Tenant administration › Roles › Settings that keeps each assignment's permissions inside its own tag. Run the Permissions Assessment Report there first; enabling the setting is a one-way change.
  • Tagged admins can't remove the last tag from an object, and they can only assign tags they hold themselves.
  • Licensing: admin accounts created after June 2021 don't need an Intune license to administer Intune; older accounts and nested group members still do.
  • Just-in-time access: Microsoft Entra Privileged Identity Management can activate the Intune Administrator role (typically within seconds) or an Intune role through PIM for Groups (up to about 15 minutes to apply).

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)