Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access 1

Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access

Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access. Role-Based Access Controls (RBAC) are one of my favorite features in Microsoft Intune.

People chose Intune hybrid instead of Intune standalone because of the lack of RBAC. The Intune team introduced RBAC features into their product back in 2017. This post will teach us how to provide read-only access to the Intune console.

I have two (2) posts covering Intune role-based access controls in detail. I recommend reading them to learn more about Intune RBAC.

However, the Intune team did excellent work in including scope features in Intune RBAC. Now, it’s getting close to SCCM RBAC features. My previous posts about Intune RBAC follow.

How to Provide Read-Only Access to Intune

RBAC helps Intune Admins control who can perform various Intune tasks within your enterprise. There are six (6) built-in Intune roles (RBAC roles). I use the default Intune role, “Read Only Operator,” to provide read-only access to the Intune console.

  1. Navigate Azure PortalMicrosoft Intune blade – Intune rolesAll roles Read-Only Operator – Assignments  – Click on + Assign.
  2. Once you click on the “+ Assign” button, a new Read-Only Operator—Role assignments blade will be displayed.
  3. Enter the following information in the blade                                                  Assignment Name = Read-Only Intune Users
    Assignment Description = Details of Read-Only Assignment Group
    Members (Groups)# = Click on the + Add button and select the Azure AD User Group, including Intune Read-Only users (my example – Intune Read-Only Users). Scope (Groups)* = Click on + Add and select the Azure AD User or/and Device group. Only the operator would be able to manage the resources in this group. More details are below.
  4. Save the Intune Role assignment by clicking the OK button

Administrators in Scope Groups Role Assignment can target policies, applications, or small
tasks to these Scope Groups. So the Intune ReadOnly user group members (in my
example screenshot) could target procedures, applications, or small functions
for the users/devices in my scoping group Intune ReadOnly. This is as per the design.

  •  Member Group users are the administrators assigned to this role.
Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access - Fig.1
Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access – Fig.1

Do You know what the Intune Scope Group Is?

Do you know what the Intune scope group is? “The users or devices that a specified person (the member) can manage.” Intune ReadOnly users can manage devices or parts of their Scope Groups in the above example.

If you are an SCCM admin, then the SCOPE option is already there in SCCM 2012 and CB console. I’ve another post that talks about Configuration manager RBAC detail.

Intune Read-Only User Experience

In this scenario, the Intune read-only user is a regular user in Azure Active Directory (without any other access). However, the user has been assigned a valid Intune (EMS) license.

I will cover all the following scenarios with Intune’s read-only user experience. The video tutorial on read-only access to Intune provides more details.

Device Enrollment Experience for Read-Only User

The user has read or view access to all the device enrollment blades. However, I noticed that the Configure MDM Push Certificate blade doesn’t allow downloading the CSR file.

The Android work enrollment experience is different from Apple’s. While trying to sign up with an Intune read-only account, I can see the following error: An error occurred requesting the Android for Work signup URL.

Windows enrollment, Terms and conditions, Enrollment restrictions, Device categories, Corporate device identifiers, and Device enrollment managers also work as expected for Intune read-only users.

Device Compliance Experience for Read-Only Users

The device compliance experience is different from the device enrollment experience. Read-only users can change the compliance policy schedule time for actions for non-compliance, but it never gets saved. Instead, it gives an error while trying to save the configuration. So we are fine!

As per my testing, the read-only user cannot assign the compliance policy to any group. For more details, refer to the Read-only Access to Intune video tutorial. However, the read-only user has access to check the status of the compliance policy on devices.

Devices Blade Experience  for Intune Read-Only User

View access for the device’s blade is intact. The user can view the properties of all devices. The Azure AD scope option may provide some opportunities to limit read-only users from checking out the properties of devices that are not in read-only users’ scope.

Also, read-only users cannot perform remote actions on devices (such as Removing company data, Factory reset, Deletion, and Remote Lock).

Device Configuration Experience  for Intune Read-Only User

Configuration profiles blade provides a classic view experience for Intune read-only users. The read-only users have view access to Overview, Properties, Assignments, Device status, User status, and Per-setting status.

The Configuration PowerShell Scripts blade provides a different experience for Intune read-only users. Like the compliance policy experience (explained above), the PowerShell scripts blade offers the option to edit or rename PowerShell script names. But we are fine with that, as Intune won’t allow read-only users to save those changes.

I had a similar experience with the PowerShell Script assignment. It allows a PowerShell script to be assigned to change the assignments, but it won’t allow the read-only user to save the changes.

Mobile Apps (Applications) Experience  for Intune Read-Only User

Intune read-only users’ mobile app experience is similar to that of device enrollment. Mobile apps Manage options provide standard view access to read-only users for Apps, App configuration policies, App protection policies, App selective wipe, and iOS app provisioning profiles.

Monitor options under mobile apps give a similar view experience for App licenses, Discovered apps, App install status, App protection status, and Audit logs.

SETUP options also give a similar view experience for iOS VPP tokens, Windows enterprise certificate, Windows Symantec certificate, Microsoft Store for Business, Windows sideloading keys, Company Portal branding, App categories, and Android for Work.

Conditional Access Experience  for Intune Read-Only User

The Conditional Access blade provides view access to read-only operators. I would love to see Azure AD Conditional Access What If work fine for read-only users. This would be very helpful from a learning perspective.

All the following items work fine as expected to provide standard view access.

Conditional Access Experience  for Intune Read-Only User
On-premises access
Users
Groups
Intune roles
Software Updates
Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access – Table 1
Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access - Fig.2
Intune Read-Only Experience Learn to Create Read-Only Operators Roles Admin Access – Fig.2

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP from 2015 onwards for consecutive 10 years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career etc…

MVPHackADoc

Learn to Fix Microsoft SCCM Intune Documentation

Let’s learn how to fix Microsoft SCCM Intune Documentation Configuration Manager ConfigMgr. How many of us complain about SCCM Intune documentation?

The documentation is not updated, relevant, etc. Here is the real opportunity to help yourself and update the SCCM and Intune documentation.

But don’t worry about the quality of the SCCM Intune documentation, as there are several steps to validate before your edits/changes are published. Hack a doc is the theme of this post 😉

Check out the Video “Learn How to Help Fixing SCCM Intune Documentation Issues“. This post will give you all the details on learning to fix Microsoft SCCM Intune Documentation.

Learn to Fix Microsoft SCCM Intune Documentation

We had a great MVPHackaDoc session with Aaron during the MVP Summit 2018. All the credits to Aaron taught me how to update SCCM/Intune documentation. I don’t recommend going around and editing or updating all the documentation. But start small before you leap.

Start Small

Learn to Fix Microsoft SCCM Intune Documentation – Video 1

What has Changed?

The Microsoft documentation service (https://docs.microsoft.com) is hosted on the GitHub platform, which improves the user experience while reading the documentation.

Even SCCM and Intune documents have been migrated to a new platform. The following is my list of key features of the new docs on the Microsoft platform.

  • Readability
  • Estimated Reading Time
  • Content and Site Navigation
  • Shortened Article Length
  • Responsive Design
  • Community Contributions
  • Social Sharing
  • Friendly URLs

How to Start Updating SCCM Intune Documentation?

I hope you read a lot of Microsoft documentation every day. You found the wrong article and want to inform the Microsoft Doc team about this incorrect information.

  • If you don’t have one, create one. It took me one and two minutes to do so.
  • You can select the GitHub Free plan during the signup process and tailor your experience to include a short introduction about yourself.
  • Open the article you identified and click the EDIT button, as I showed in the video tutorial. You should open the article from the same browser you are already logged in to from your GitHub account.
  • Once you click on the EDIT button on that article, it will redirect to the GitHub editor.
  • You will perform all the updates in the GitHub editor.

Identify the Article and Start Contributing

How to Contribute to SCCM Intune Documentation

As Aaron mentioned in his “MVP Hack a Doc” session, start small. Standard GitHub accounts may not have access to edit live document code. And you will get the following error when you try to edit or update an article.

  • You’re editing a file in a project you don’t have write access to.
  • Submitting a change to this file will write it to a new branch in your fork.
  • AnoopCNair/SCCMdocs so that you can send a pull request.

As I have shown in the “Hack A Doc video, A perfect example of raising an issue from Jason. He raised a problem and a documentation BUG was filed to fix this issue. 

I also tried creating a pull request, but I think that requires more access to edit the master file. A normal GitHub account may not have access to proceed with a pull request.

Another interesting thing I learned was how to select the best title, title suffix, description, and ms. Custom, ms. Date, and Ms. Prod for technical articles. As Aaron suggested, we can start doing the following things:-

Start Doing the Following Things
Clarifications
Examples
SDK, PowerShell
Guidance tips
Translations
See something, fix something
Learn to Fix Microsoft SCCM Intune Documentation – Table 1

I have tried raising an issue with documentation, which is the best and easiest part I learned during the MVPHackaDoc session. I have more details about the problems raised in Hack A Doc’s video tutorial.

Another useful option trying to try to track the documentation issues with th GitHub account. So we can rest assured that Microsoft is aware of this bug and will fix it soon. Following is the file structure of the GitHub article (for example) SCCMdocs/sccm/core/plan-design/hierarchy/accounts.md .

Start Contributing = Raising an Issue

Learn to Fix Microsoft SCCM Intune Documentation - Fig.1
Learn to Fix Microsoft SCCM Intune Documentation – Fig.1

Resources

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP from 2015 onwards for consecutive 10 years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career etc…

Free LinkedIn Learning Courses for SCCM Intune 2

Free LinkedIn Learning Courses for SCCM Intune

Free LinkedIn Learning Courses for SCCM Intune. I agree with the following sentence, so I’m sharing my experience with LinkedIn learning. Microsoft MVPs are notorious for passionately sharing their knowledge with the world.

In this post, we will learn about free LinkedIn learning courses available for SCCM and Intune (Learn SCCM Intune).

SCCM is great, and it will not die, as per Microsoft. But don’t abandon Intune learning. I strongly recommend going through the Intune learning process.

Microsoft MVP Award program celebrated its 25th anniversary. As part of the 25th-anniversary celebrations, LinkedIn unlocked 15 Courses Covering Key Technology Skills. The following is the list of 15 courses that LinkedIn has unlocked. This post will discuss more details about SCCM and Intune free study materials.

Introduction

I have a full-blown post about systematic learning of SCCM and Intune. The approach to learning should be the same as I mentioned in the post, which was published back in 2015. I learned SCCM the hard way. There was no one to handhold and teach me.

Great Learning – What to Learn Intune? Great Resource Around you!
(1) LinkedIn Learning Courses for Microsoft Intune
(2) Learning How to Learn SCCM Intune Azure
(3) Learn Intune Beginners Guide MDM MAM MIM
(4) Microsoft Intune for SCCM Admins Part 1
Free LinkedIn Learning Courses for SCCM Intune – Table 1

My Favourites Microsoft System Center Configuration Manager… SCCM CB Learning Microsoft Enterprise Mobility Suite (Azure AD and Intune) Office 365 for Administrators: Supporting Users Part 1 Windows 10: Deploy and Manage Virtual Applications Productivity Apps Excel 2016: Get & Transform PowerPoint: Designing Better Slides OneNote Tips and Tricks Visio Tips and Tricks Automation & Developer Microsoft Graph for Developers API Development in .NET with GraphQL ASP.NET Core: Razor Pages ASP.NET Core New Features Microsoft Cybersecurity Stack: Advanced Identity… Microsoft Cloud Services: Troubleshooting Online… Building and Securing RESTful APIs in ASP.NET Core

How to Start Learning SCCM and Intune?

I never got a chance to attend training before being pushed to work on SCCM. That is a different experience, as I explained in the future of SCCM/Intune jobs post.

How Do You Get Access to Free SCCM and Intune Video Courses?

These 15 courses are free only for a limited period. As per the MVP Award program post, they are unlocked for the general public until the middle of April! So don’t waste time—start learning SCCM/Intune using LinkedIn study materials.

In the video tutorial here, I explain how to start learning through LinkedIn courses. However, the SCCM course won’t work from the following link. I recommend using the link I provided in the next section of the post.

  1. Open https://learning.linkedin.com/events/2018/03/msft-mvp-global-summit
  2. No need to log in to LinkedIn to access these courses (anonymous access is allowed)
  3. Open any of the 15 free courses available
Free LinkedIn Learning Courses for SCCM Intune - Fig.1
Free LinkedIn Learning Courses for SCCM Intune – Fig.1

Start Free SCCM Online Course

To start the cause, you don’t need to log in with your LinkedIn account. Also, you don’t need to start the trial version of LinkedIn learning for a month. You can access the SCCM course from a private browser without logging in.

  • To start the Free SCCM online course from a private browser
  • Content of the SCCM CB Course
  • Introduction (More details about SCCM CB content at the bottom of the post)
  1. Planning and Deploying a Standalone Primary Site
  2. Designing and Deploying a Multiple-Site Hierarchy
  3. Planning Resource Discovery and Client Deployment
  4. Managing Content and Replicating Data in Configuration Manager
  5. Configuring Internet and Cloud-Based Client Management
  6. Maintaining and Monitoring SCCM CB
  7. Upgrading to SCCM CB
    Conclusion

Start Free Intune Online Course

Intune course is part of EMS. So, the EMS course includes both Azure AD and Microsoft Intune. I have an Intune starter kit that can help you start learning Intune from scratch. More details are available in the Intune guide for beginners in the enterprise mobility world.

  • Start the course Directly from the following link
  • Content of the Intune Course

Microsoft Intune

With Intune, you can easily manage apps and devices. You can also configure Intune to manage iOS and Android. More details are explained below.

  • Manage apps and devices with Intune – 3m 30s
  • Configure Intune to manage iOS and Android – 4m 0s
  • Build and deploy a basic policy for iOS or Android – 5m 17s
  • Deploy and manage mobile apps -5m 15s
  • Enrol your first device – 2m 45s

Resource

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP from 2015 onwards for consecutive 10 years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career etc…