User Access Control & PIM Integration
User Access Control & PIM Integration
Last updated
Configure secure multi-user access with role-based permissions and Privileged Identity Management
Intune Assistant supports secure multi-user environments through proper access control and integration with Microsoft Entra Privileged Identity Management (PIM).
Only the user who completes onboarding can initially access Intune Assistant, except when a user consents the app registrations for the whole organization.
The service principal is created with restricted access by default
Additional users must be explicitly granted access
However, Intune Assistant has delegated permissions and acts like the current logged in user, it is HIGHLY recommended to NOT consent the app registrations for the whole organisation. By default it is only consented for the user that runs the onboarding process. The builder is NOT responsible for any security related misconfiguration.
Least Privilege: Grant minimum required access
Explicit Assignment: Never rely on organization-wide consent
Role-Based Access: Use PIM for time-limited administrative access
Go to Azure Portal or Entra Admin Center
Select Enterprise Applications
Managing Admin Consent\ \ Handle consent requirements when new permissions are added to IntuneAssistant
Last updated