Most tenants start with a handful of people holding the Microsoft Entra Intune Administrator role, and that is fine until the helpdesk, a regional IT team and the packaging team all need access too. Intune role-based access control (RBAC) lets you give each group exactly the permissions and the visibility it needs. In this post I'll explain how roles, assignments and scope tags work together, walk through three common delegation designs, and show how to audit and verify the result.
How it works#
Intune RBAC has three moving parts, and confusing them is the root of most delegation problems:
- Roles define what an admin can do. Permissions are grouped by category (Mobile apps, Device configurations, Remote tasks, Audit data and so on) with actions such as Read, Create, Update, Delete and Assign. Built-in roles are identical in every tenant and can't be edited; custom roles can contain any combination of permissions.
- Role assignments connect a role to people. Each assignment has Members (the Microsoft Entra security groups whose users receive the role), Scope (Groups) (the user and device groups those admins are allowed to manage and target) and Scope (Tags).
- Scope tags define which objects an admin can see. An admin only sees policies, apps, devices and other objects that carry at least one tag matching their role assignment. Tags are free-form labels you create under Tenant administration › Roles › Scope (Tags).
Two details about the Default scope tag matter a lot. First, Intune adds it automatically to every untagged object that supports tags, so "untagged" really means "tagged Default". Second, an admin whose role assignment has no scope tags effectively has all tags and sees everything their permissions allow. Scope tags only start filtering once you add them to the assignment.
Remember also that Intune RBAC doesn't restrict Microsoft Entra roles: Global Administrator and Intune Administrator keep full access regardless of tags. Microsoft recommends keeping those roles for the rare tasks that require them and using Intune roles for day-to-day work.
Step-by-step#
Step 1: Pick a role, or build one#
Review the built-in roles under Tenant administration › Roles › All roles. The ones you'll use most are Help Desk Operator (remote tasks, assigning apps and policies), Policy and Profile Manager, Application Manager, Endpoint Security Manager and Read Only Operator. Intune Role Administrator is the only Intune role that can create role assignments. If no built-in role fits, select Create for a custom role, or tick an existing role and choose Duplicate to copy its permissions and trim them. Creating or editing roles requires the Microsoft Entra Intune Administrator role, and if Multi Admin Approval is enabled for RBAC, a second admin has to approve the change.
Step 2: Create scope tags#
Go to Tenant administration › Roles › Scope (Tags) › Create. Name the tag after the boundary it represents (a region, a business unit, a device class). On the Assignments page you can select device groups whose members automatically receive the tag. Note that these automatic assignments overwrite manually assigned tags, and a device in several tagged groups receives all of those tags.
Step 3: Create the role assignment#
Open the role, select Assignments › Assign, and fill in the three pages: Admin Groups (members), Scope Groups (prefer specific groups over Add all users or Add all devices) and Scope tags. A role assignment and an object can each carry up to 100 tags.
Step 4: Tag the objects#
For most objects, scope tags live under Properties › Scope (Tags) › Edit. Two shortcuts help here: when a scoped admin creates an object, Intune stamps it with that admin's tags automatically, and apps bought through Apple Volume Purchase Program inherit the tags of their token. A few object types don't support tags at all: corporate device identifiers, Windows Autopilot devices, device compliance locations and Jamf devices.
Common delegation designs#
| Team | Role | Scope (Groups) | Scope (Tags) | Why it works |
|---|---|---|---|---|
| Helpdesk | Help Desk Operator, or a custom role with Managed devices Read plus the Remote tasks you allow (Sync devices, Reboot now, Remote lock, Collect diagnostics) | All users and all devices, or the regions they support | Default plus any regional tags | They can act on devices but can't create or change policy |
| Regional admins | Policy and Profile Manager (often also Application Manager) | Groups containing that region's users and devices | The regional tag only | They see and manage only objects tagged for their region; new objects they create are tagged automatically |
| App packagers | Application Manager, or a custom role with Mobile apps Create/Read/Update/Delete/Relate but no Assign | A pilot group, so they can only target test devices | An "Apps" tag | They build and test packages; production assignment stays with the platform team |
Tip: If a regional admin must manage exclusion groups, each excluded group has to be nested inside one of the assignment's scope groups or listed as a scope group itself. Otherwise the exclusion can't be created.
Verify#
Don't guess what an admin can do; check it. Under Tenant administration › Roles › Monitor you'll find three views: My permissions (your own effective permissions), Roles by permission (pick a permission and action to see which assignments and groups grant it) and Admin permissions (enter a user and see everything they hold). Then sign in with a test account that is a member of the admin group and confirm:
- Only the expected policies, apps and devices appear in the lists.
- Creating a test profile stamps it with the right scope tag automatically.
- Assigning it offers only groups within the Scope (Groups).
- Actions outside the role (for example, deleting a device) are missing or denied.
Every create, update, delete, assign and remote action lands in Tenant administration › Audit logs. Filter by Category (there is a dedicated Role category) and Activity, or export the list to CSV. Audit data can also be routed to Azure Monitor from Reports › Diagnostics settings, and the Graph auditEvents API returns up to two years of history. Reading audit logs requires the Audit data Read permission or the Intune Administrator role.
Tips & gotchas#
- Untagged objects are the usual leak. Anything without a tag carries Default, and any assignment that includes Default sees it all. Keep Default for the central team only, and tag everything you delegate.
- Groups are not tags. Scope (Groups) limits who an admin can target; Scope (Tags) limits what they can see. A regional admin with the right tags but the wrong scope groups will see their policies and be unable to assign them, and vice versa.
- Multiple assignments add up. By default, when an admin holds several assignments in the same permission category, Intune merges the permissions across all their tags, which can grant more than you intended. In March 2026 Intune added an opt-in Scoped permissions preview under Tenant administration › Roles › Settings that keeps each assignment's permissions inside its own tag. Run the Permissions Assessment Report there first; enabling the setting is a one-way change.
- Tagged admins can't remove the last tag from an object, and they can only assign tags they hold themselves.
- Licensing: admin accounts created after June 2021 don't need an Intune license to administer Intune; older accounts and nested group members still do.
- Just-in-time access: Microsoft Entra Privileged Identity Management can activate the Intune Administrator role (typically within seconds) or an Intune role through PIM for Groups (up to about 15 minutes to apply).