Role-based access control
Rollenbasierte Zugriffssteuerung
Role-based access control (RBAC) governs which actions an administrator may perform in Intune - via built-in roles (e.g. Help Desk Operator, Policy and Profile Manager) or custom roles. Combined with scope tags, it cleanly splits management across teams and locations (least privilege).
Path in the Intune admin center
📍 Mandantenverwaltung › RollenHands-on tasks
- Troubleshooting + support - use the help-desk cockpitMicrosoft Intune - Hands-on Course · Module 01
- Review RBAC least privilegeMicrosoft Intune - Hands-on Course · Module 04
- Control local admin rights on Entra-joined devicesMicrosoft Intune - Hands-on Course · Module 08
- FileVault - disk encryption for MacsMicrosoft Intune - Hands-on Course · Enroll macOS devices
- Test the BitLocker recovery processMicrosoft Intune - Hands-on Course · Module 14
- Windows LAPS - manage the local admin passwordMicrosoft Intune - Hands-on Course · Windows LAPS - manage the local admin password
- Lock down access to the LAPS password (least privilege)Microsoft Intune - Hands-on Course · Windows LAPS - manage the local admin password
- Audit LAPS password accessMicrosoft Intune - Hands-on Course · Windows LAPS - manage the local admin password
- Understand the concept and componentsMicrosoft Intune - Hands-on Course · Cloud PKI
- Set up Remote Help and secure it with RBACMicrosoft Intune - Hands-on Course · Remote Help (Concept)
- Audit Remote Help sessionsMicrosoft Intune - Hands-on Course · Remote Help (Concept)
- Understand the concept (license-bound)Microsoft Intune - Hands-on Course · Endpoint Privilege Management (EPM)
- Derive targeted elevation rules from EPM reportsMicrosoft Intune - Hands-on Course · Endpoint Privilege Management (EPM)
- Review and approve EPM requestsMicrosoft Intune - Hands-on Course · Endpoint Privilege Management (EPM)
- Create a scope tag and control visibilityMicrosoft Intune - Hands-on Course · Scope tags - distributed IT administration
- Delegated site IT with role, scope groups, and scope tagsMicrosoft Intune - Hands-on Course · Scope tags - distributed IT administration
- Test scope tag visibility with a test adminMicrosoft Intune - Hands-on Course · Scope tags - distributed IT administration
- Design governance rules for Intune changesMicrosoft Intune - Hands-on Course · Governance, audit, and Multi Admin Approval
- Plan a quarterly review for roles and critical policiesMicrosoft Intune - Hands-on Course · Governance, audit, and Multi Admin Approval
- Find your own change again in the audit logMicrosoft Intune - Hands-on Course · Governance, audit, and Multi Admin Approval
- Use Copilot in Intune with controlsMicrosoft Intune - Hands-on Course · Use Copilot in Intune
- Use Copilot for policy conflicts with controlsMicrosoft Intune - Hands-on Course · Use Copilot in Intune
- Control Intune changes as an operating processMicrosoft Intune - Hands-on Course · Intune release and change management
- Perform a release impact review for new Intune featuresMicrosoft Intune - Hands-on Course · Intune release and change management
- Plan a first Intune analysis with Microsoft GraphMicrosoft Intune - Hands-on Course · Graph automation hands-on
- Perform a recurring Intune tenant health reviewMicrosoft Intune - Hands-on Course · Tenant health review
- Prioritize findings from the tenant health reviewMicrosoft Intune - Hands-on Course · Tenant health review
- Evaluate Intune in regulated cloud environmentsMicrosoft Intune - Hands-on Course · Sovereign clouds and regulated environments
- Create a feature approval process for regulated tenantsMicrosoft Intune - Hands-on Course · Sovereign clouds and regulated environments
- Ops round 5: hand over open findings, dismantle the lab objectsMicrosoft Intune - Hands-on Course · Module 24
- Choose and justify a group, filter, or scope tagMicrosoft Intune - Hands-on Course · Module 26
Jump straight to the matching course task (sign-in required).
On Microsoft Learn
Related terms