Lab 22: Intune RBAC and Scope Tags

Delegated scoped Intune endpoint-support permissions to the Service Desk through the Help Desk Operator role, a dedicated administrator group, a Windows pilot scope group and a custom scope tag, then validated Chloe Bennett's access boundary.

Overview

This lab extends the existing Service Desk permission model into Microsoft Intune. Chloe Bennett and Daniel Smith were already established as first-line analysts, but endpoint administration required a separate Intune role assignment rather than broad tenant administration.

The built-in Help Desk Operator role was assigned to a dedicated security group. The assignment used GRP_Intune_Windows_Pilot_Devices as its scope group and ST-Windows-Pilot as its scope tag, limiting the new Intune operational permissions to the Windows pilot context.

Permission interaction: Chloe already held the Microsoft Entra Helpdesk Administrator role from an earlier identity lab. That role allowed read-only Intune visibility. The before-and-after validation therefore tested whether operational device actions were disabled or enabled; it did not claim that the new scope tag removed separate read access granted by Microsoft Entra.

Objective

The objective was to implement least-privilege endpoint support by separating identity-helpdesk permissions from Intune device-management permissions. The lab also demonstrates how administrator groups, scope groups and scope tags combine within an Intune role assignment.

Environment

Environment
ComponentValue
CompanyNietz Ltd
Tenant domainnietz.co.uk
Management platformMicrosoft Intune
Built-in Intune roleHelp Desk Operator
Administrator groupGRP_Intune_Helpdesk_Operators
Administrator group membersChloe Bennett and Daniel Smith
Scope groupGRP_Intune_Windows_Pilot_Devices
Custom scope tagST-Windows-Pilot
Role assignmentRA-Intune-Helpdesk-Windows-Pilot
Validation accountChloe Bennett — [email protected]
Validation deviceCL2
Previous lab dependencyLab 21: Intune Application Deployment and Microsoft 365 Apps
Next labLab 23: Edge Browser Security Baseline

Configuration and Evidence

1. Help Desk Operator Role Identified

I opened the built-in Microsoft Intune Help Desk Operator role and confirmed that it was available for assignment.

Microsoft Intune Help Desk Operator built-in role overview
Figure 1Built-in Help Desk Operator role selected in the Intune admin center.

2. Help Desk Operator Permissions Reviewed

I reviewed the role description and permission categories before assigning it. The screenshot shows an excerpt from the upper portion of the full permissions list; further permissions continue below the visible area.

Excerpt of Microsoft Intune Help Desk Operator permissions
Figure 2Help Desk Operator description and an excerpt of its built-in permissions.
Role purpose: The built-in role is intended for user and device support, including permitted remote tasks and support of applications or policies.

Baseline Permission Check

3. Device Actions Disabled Before Intune RBAC

Before Chloe was added to the new Intune administrator group, I signed in as her and opened CL2. Her existing Microsoft Entra Helpdesk Administrator role allowed the device record to be viewed, but the Intune operational controls were unavailable.

Chloe Bennett viewing CL2 with Intune device actions disabled before the new RBAC assignment
Figure 3Read-only baseline: CL2 was visible, while remote device actions remained disabled.

Scoped RBAC Configuration

4. Dedicated Intune Helpdesk Group Created

I created GRP_Intune_Helpdesk_Operators as an assigned cloud security group for Intune administrative delegation.

GRP Intune Helpdesk Operators security group listed in Microsoft Entra
Figure 4Dedicated cloud security group created for Intune helpdesk operators.

5. Service Desk Members Added

I added Chloe Bennett and Daniel Smith as direct members. The group contains both a synchronised on-premises identity and a cloud-only identity.

Chloe Bennett and Daniel Smith listed as members of the Intune helpdesk operators group
Figure 5Chloe Bennett and Daniel Smith confirmed as direct Intune helpdesk group members.

6. Windows Pilot Scope Tag Reviewed

I configured the custom ST-Windows-Pilot scope tag and assigned it to GRP_Intune_Windows_Pilot_Devices. This connected the custom scope-tag context to the managed Windows pilot devices.

ST Windows Pilot scope tag review showing assignment to the Windows pilot device group
Figure 6Custom scope tag reviewed with the Windows pilot device group assignment.
Scope note: Scope tags filter Intune objects within the Intune RBAC assignment. They do not cancel access that a user receives independently through a Microsoft Entra role.

7. Custom Scope Tag Created

I created ST-Windows-Pilot alongside the built-in Default scope tag.

ST Windows Pilot custom scope tag listed in Microsoft Intune
Figure 7Custom Windows pilot scope tag created successfully.

8. Scoped Role Assignment Reviewed

I configured RA-Intune-Helpdesk-Windows-Pilot with the dedicated helpdesk group as the administrator group, the Windows pilot device group as the scope group and ST-Windows-Pilot as the scope tag.

Review of the Help Desk Operator role assignment with admin group scope group and scope tag
Figure 8Complete role-assignment relationship reviewed before creation.

9. Scoped Help Desk Operator Assignment Created

I created the role assignment and confirmed that its administrator group and Windows pilot scope group were active, with the custom scope tag attached.

Created Intune Help Desk Operator role assignment showing member group scope group and scope tag
Figure 9Scoped Help Desk Operator assignment created and active.

Validation

10. Scoped Intune Device Actions Enabled

After Chloe was added to GRP_Intune_Helpdesk_Operators and a fresh session was opened, I returned to CL2. The command bar and expanded actions menu now showed permitted device-management actions as enabled.

Chloe Bennett viewing CL2 with Intune Help Desk Operator actions enabled after the scoped RBAC assignment
Figure 10Post-change validation showing Intune operational actions enabled for Chloe on CL2.
Safe validation: The enabled controls were used as evidence of the permission change. No destructive action such as Wipe, Retire, Fresh Start or Autopilot Reset was submitted.

Validation Result

The lab confirmed a clear before-and-after permission change. Chloe could already read the CL2 record through her existing Microsoft Entra Helpdesk Administrator role, but remote Intune actions were disabled before the new role assignment. After membership in the dedicated Intune administrator group, operational actions became available for the Windows pilot device through the scoped Help Desk Operator assignment.

Key Technical Outcomes

Summary

  • I established the original read-only support baseline for Chloe Bennett.
  • I created a dedicated Intune helpdesk group containing Chloe Bennett and Daniel Smith.
  • I created ST-Windows-Pilot and linked it to the Windows pilot device group.
  • I assigned the built-in Help Desk Operator role through a scoped Intune RBAC assignment.
  • I confirmed that operational device actions became available on CL2 after the assignment.
  • I retained the distinction between Microsoft Entra identity administration and Microsoft Intune endpoint administration.