User Access Control & PIM Integration

Administration

User Access Control & PIM Integration

Configure secure multi-user access with role-based permissions and Privileged Identity Management

IntuneAssistant supports secure multi-user environments through proper access control and integration with Microsoft Entra Privileged Identity Management (PIM).

  • Only the user who completes onboarding can initially access IntuneAssistant

  • The service principal is created with restricted access by default

  • Additional users must be explicitly granted access

  • Least Privilege: Grant minimum required access

  • Explicit Assignment: Never rely on organization-wide consent

  • Role-Based Access: Use PIM for time-limited administrative access

1
2

Locate IntuneAssistant Service Principals

  • Search for "Intune Assistant"

  • You'll find two applications:

    • Intune Assistant (Main Application)

    • Intune Assistant API (Backend Service)

3

Assign Users to Both Applications

  • Assign users to both the Intune Assistant and Intune Assistant API applications as needed.

Managing Admin Consent\ \ Handle consent requirements when new permissions are added to IntuneAssistant

Data & Privacy\ \ Our commitment to data privacy and security with minimal data storage and no data leaving your tenant