For the complete documentation index, see llms.txt. This page is also available as Markdown.

Needed Permissions

Intune Assistant

Needed Permissions

Complete guide to configuring granular permissions for Intune Assistant users

Permissions Overview

Learn how to configure the required permissions for Intune Assistant and how to set up granular permissions for users in your organization.

Required Graph API Permissions

Intune Assistant requests Microsoft Graph API permissions in stages: a core set the first time you sign up, and a couple of extra permissions the first time you use a feature that needs them. If you see a consent prompt again after your initial setup, it's one of these additional feature requests — not a repeat of something you already granted.

Core permissions (requested when you sign up)

Permission
Type
Description

Group.Read.All

Delegated

Read group memberships and properties

GroupMember.Read.All

Delegated

Read group membership relationships

User.ReadBasic.All

Delegated

Read basic user information like name and email

RoleManagement.Read.Directory

Delegated

Read Microsoft Entra ID directory role assignments

AuditLog.Read.All

Delegated

Read Microsoft Entra ID and Intune audit logs

Directory.AccessAsUser.All

Delegated only

Access directory data on behalf of the signed-in user

DeviceManagementConfiguration.Read.All

Delegated

Read Intune configuration profiles and baselines

DeviceManagementScripts.Read.All

Delegated

Read PowerShell and shell scripts

DeviceManagementRBAC.Read.All

Delegated

Read Intune role-based access control assignments

DeviceManagementApps.Read.All

Delegated

Read managed applications and app configurations

DeviceManagementServiceConfig.Read.All

Delegated

Read device management service configuration

DeviceManagementManagedDevices.Read.All

Delegated

Read managed device inventory

Policy.Read.ConditionalAccess

Delegated

Read Conditional Access policies

ConfigurationMonitoring.ReadWrite.All

Delegated

Create and manage configuration drift monitors

Mostly read-only

Most core permissions are read-only. Two exceptions: Directory.AccessAsUser.All lets Intune Assistant act on Microsoft Graph on your behalf using your own directory permissions, and ConfigurationMonitoring.ReadWrite.All is needed for Drift Monitoring, which is included free with every account.

Drift Monitoring permissions (requested the first time you set up a monitor)

Drift Monitoring is free and included with every account, but it needs two extra permissions the first time you configure a monitor, so it can create and manage the background service account that watches for configuration changes:

Permission
Type
Description

Application.ReadWrite.All

Delegated

Create and manage the background service account used for drift monitoring

AppRoleAssignment.ReadWrite.All

Delegated

Assign the permissions that background service account needs to operate

Assignments Manager permissions (requested if you purchase this module)

Assignments Manager needs write access to manage and migrate policy assignments, in addition to the core permissions above:

Permission
Type
Description

DeviceManagementConfiguration.ReadWrite.All

Delegated

Create, update, and migrate Intune configuration profiles

DeviceManagementApps.ReadWrite.All

Delegated

Create, update, and migrate app assignments

DeviceManagementServiceConfig.ReadWrite.All

Delegated

Update device management service configuration

DeviceManagementScripts.ReadWrite.All

Delegated

Create, update, and migrate PowerShell and shell scripts

DeviceManagementRBAC.ReadWrite.All

Delegated

Update Intune role-based access control assignments

Configuring Granular User Permissions

Instead of giving users full Intune Administrator permissions, you can configure granular role-based access control (RBAC) permissions. This follows the principle of least privilege.

Understanding Intune RBAC

Microsoft Intune uses role-based access control to determine what actions users can perform. Each role contains:

  • Permissions: What actions can be performed

  • Scope: Which resources the role applies to

  • Assignments: Which users or groups have the role

Required Intune Roles for Intune Assistant

Since Intune Assistant only reads data, users need roles with read permissions for the following categories:

Allows reading device configuration profiles and compliance policies.

Required permissions:

  • Device configuration policies: Read

  • Device compliance policies: Read

  • Device enrollment: Read

Application Reader

Allows reading application management data.

Required permissions:

  • Mobile applications: Read

  • Mobile application management policies: Read

Reports Reader

Allows reading reports and analytics data.

Required permissions:

  • Reports: Read

Conditional Access Reader

Allows reading Conditional Access policies.

Required permissions:

  • Conditional Access: Read

Creating a Custom Role

For optimal security, create a custom role with only the required read permissions:

1
2

Create new role

  • Click Create

  • Enter role name: Intune Assistant Reader

  • Add description: Read-only access for Intune Assistant users

3

Configure permissions

  • Device configuration policies: Read ✓

  • Device compliance policies: Read ✓

  • Device enrollment: Read ✓

  • Mobile applications: Read ✓

  • Mobile application management policies: Read ✓

  • Reports: Read ✓

  • Organization: Read ✓

4

Set scope and assignments

  • Define which users/groups should have this role

  • Set appropriate scope tags if needed

Built-in Roles Alternative

If you prefer using built-in roles, assign users to:

  • Intune Service Administrator (full read/write - not recommended)

  • Reports Reader (limited to reports only)

  • Global Reader (read access across Microsoft 365)

Recommended approach

We recommend creating a custom role with only the required read permissions to follow the principle of least privilege.

Troubleshooting

Common permission issues:

Issue
Solution

User cannot see any data

Check if user has required Intune role assigned

Missing device configurations

Verify DeviceManagementConfiguration.Read.All permission

Missing applications

Check DeviceManagementApps.Read.All permission

Intune Assistant requires admin consent for the Graph API permissions. Ensure that a Global Administrator has granted consent for the application in your tenant. New features may require additional permissions, if a required consent is missing you will get notified in the right bottom corner. (see the screenshot below) Then run the consent again.

For information about that process, check the Managing Admin Consent documentation.

Additional Resources

Best practice

Regularly review and audit user permissions to ensure they align with current job responsibilities and security requirements.

Last updated