Intune Teams Roles Responsibilities Endpoint Manager | Microsoft Intune Default Roles? I will discuss Intune Modern Device management roles and responsibilities in this post. Although the first version of Intune was released in 2011 (or before that), the large-scale adoption of Microsoft Intune started in the last two years.
I thought it would be better to spend some time defining Intune modern device management job roles within an organization. This post will help create a baseline for Microsoft Intune R & R for your organization. In this post, we will see “Intune Teams Roles Responsibilities“.
Modern device management roles are similar to SCCM/ConfigMgr roles but not the same. As a starting point, we can take some of the job roles from SCCM and then expand that list to produce more comprehensive modern device management-related roles and responsibilities. This will also help build Intune modern device management teams within your organization.
This post explains the roles and responsibilities in Intune Teams Endpoint Manager, focusing on the default roles provided by Microsoft Intune. These roles define the permissions and tasks that users can perform within Intune.
This covers many hours-long training videos and Free Intune Design Decisions Training Videos. We also provide Free SCCM Training. We have also prepared the Top 50 Latest SCCM Interview Questions and Answers and Top 50 Latest Intune Interview Questions And Answers.
- Intune Supported Device Platforms and Custom Baselines Options
- Intune Supported Enrollment Methods for Windows, iOS, Android, MacOS, Linux, and ChromeOS
- Intune Design Decisions Free Training | Version 1 Starter Kit | Basic
Table of Contents
Intune Teams Roles Responsibilities Endpoint Manager | Microsoft Intune Default Roles
The following are the Intune team’s roles and responsibilities in Intune/AAD/Device management at a high level. I have segregated these roles and responsibilities depending on each feature of Intune. You can segregate these into different support organizations per your organization’s requirements.
Intune L1/L2 teams within your organizations may complete some tasks. However, some tasks require more technical skills, which Intune/Device Management L3 teams would handle.
What are the Intune Team’s Roles and responsibilities?
Overall, I will segregate Intune roles into two(2). I have an Intune RBAC post to help you understand the security permissions needed for each role. More granular roles and permissions can help you define the Intune RACI matrix for your organization.
- Intune Help Desk – First-level support
- Intune Admin – Second or Third-Level Support
User Management Application Creation and Deployment/Assignment Service Administration Mobile Application Management Device/Profile Management Conditional Access Company Resource Access Software Update Management
Intune/AAD – User Management – Intune Teams Roles Responsibilities
Understanding the roles and responsibilities is crucial in managing Intune and Azure Active Directory (AAD) user accounts. Intune Teams provide various roles with specific responsibilities to ensure smooth user management.
Intune/AAD – User Management |
---|
Onboarding of users (The onboarding process will be different for each organization) |
User Licenses (Assigning licenses can be automated soon) |
Create, edit or delete Azure Active Directory (AAD) user/Device groups |
Create, edit or delete Azure Active Directory Dynamic user/Device groups |
Intune/AAD – Application Creation and Deployment/Assignment
In Intune and Azure Active Directory (AAD), creating and deploying/assigning applications is crucial to managing your organization’s devices. You need to develop applications and then deploy or assign them to users or devices regarding application management.
- Upload and Configure LOB applications (Windows, iOS, and Android)
- Upload and Configuring Store applications (Windows, Apple, and Google )
- Deploy LOB applications to a computer/mobile devices (iOS, WP, and Android)
- Deploy Store applications to a mobile device (Windows 10, iOS, WP, and Android)
- Deploy LOB/Store applications to a group of users (AAD user groups)
- Monitor application deployment status
Intune – Service Administration
Microsoft Intune is a cloud-based service within the Enterprise Mobility + Security (EMS) suite that focuses on mobile device management (MDM) and mobile application management (MAM). The list below provides more details.
- Subscriptions and licenses
- Apple APN cert Management (Once a year – Use generic mailbox to create APN certs)
- Reset mobile device authority (In case you want to change MDM authority)
- Provisioning
- Domain Management
- Role-based access controls (RBAC) assignments for different Intune roles
- Android for Work – configure and set A4W device management
- Device settings configuration to enable Azure AD join (for Windows 10 devices)
- MDM auto-enrollment configurations (for Windows 10 devices)
- Company portal Branding
- Terms and Conditions setup
- Windows Hello for Business
- Enrollment Restriction Rules
- Service availability
- Alerts and notifications
- Reporting – Power BI and OMS
Intune – Mobile Application Management
In Intune, mobile application management (MAM) is a critical component of managing applications on mobile devices. It allows organizations to control and protect corporate data within mobile apps without managing the entire device.
- MAM Policy creation, edition, and deletion of Managed Applications
- Deployment/Assignment of managed applications to AAD groups
- LOB Application Wrapping for iOS and Android managed applications
- Wrap the LOB apps using iOS SDK
- Wrap the LOB apps using Android SDK
Intune – Device/Profile Management
In Intune, device and profile management are crucial for maintaining control and security over the organization’s devices. This involves creating, maintaining, updating, deploying, and, when necessary, deleting policies.
- Configuration policies:-
Device Restriction
Wi-Fi Profile
VPN/Per APP VPN Profile
SCEP Profiles
Custom Policies - Compliance Policies:-
iOS Compliance Policies
Android Compliance Policies
Windows Compliance Policies - Device Life Cycle
- Enroll the mobile devices (iOS, WP, Windows 10, and Android)
- Retire and Wipe Devices
AAD/Intune – Conditional Access
Conditional access is a powerful feature in Azure Active Directory (AAD) and Intune that helps organizations control access to their resources based on certain conditions. The list below provides more details.
- Create, Maintain, Update, Deploy and Delete CA policies
- CA for Windows devices
- CA for Android devices
- CA for iOS devices
- CA for MAC OS devices?
Intune/NDES/CA – Company Resource Access
Intune, NDES, and CA enable organizations to implement strong security measures, such as certificate-based authentication, to control access to sensitive data and resources.
- Exchange on-premises connector
- Office 365 connector
- NDES connector
Intune/Analytics – Software Update Management
In Intune, Analytics plays a crucial role in Software Update Management, ensuring that devices are updated with the latest software patches and updates. Intune Analytics provides insights into the update status of devices, allowing administrators to monitor and manage software updates effectively. T
- Software Update Deployment in the traditional way using Intune client
- Software Update Scheduling via MDM policies
- Update Approval using Windows 10 CSPs
We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.
Author
Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.
Notify me for new topics
Hi Anandh – There are several options to get notified about posts in this site.
1. Check out option for “Subscribe to Blog via Email” – this will send you an email whenever we publish a post
2. Like our Facebook page to notify about Videos and new posts https://www.facebook.com/ConfigMgr2012/
3. Follow me on Twitter – https://twitter.com/anoopmannur
4. Connect with me via LinkedIn – https://www.linkedin.com/in/anoopcnair/
5. Google Plus – https://plus.google.com/+Anoopcnair
6. YouTube – https://www.youtube.com/user/AnoopMannur/
Is this updated one or pretty old
What is the information you are looking for pls ?
Looking for roles and responsibilities for latest Intune.. As we know changes happen with additional capabilities such as managing bitlocker, patching, security firewall, windows defender management..
Ok. Those are not covered in this post. But you might be able to get more details from ignite video mentioned in the following post https://www.anoopcnair.com/intune-reporting-strategies-advanced-reporting/
Question – is there a specific role to allow only to Wipe and Sync an iOS device?
I think you can create custom roles for wiping the iOS devices and scope tags
Is there a custom role setting for admins to only be able to wipe Mobile devices and not Computers ?
I don’t have anything ready for this particular scenario. But you can refer to sample one here. I have created Intune custom admin role for helpdesk user https://howtomanagedevices.com/sccm/2066/custom-intune-helpdesk-operator/
Hi Anoop,
What are the roles and responsibilities of the L1 engineer in INTUNE