Identity roles and privileges for a Windows 365 cloud PC
In order to use a Windows 365 cloud PC, your Azure AD configuration should be hybrid Azure AD-joined (HAADJ) to enroll your cloud PCs into Intune.
Azure Subscription Owner
Users with this role have global access to all resources in the Azure subscription. These rights are needed for the initial setup of Windows 365.
This role grants users full access to manage all resources, including the ability to assign roles in Azure RBAC.
Intune Administrator
Users with this role have global permissions within Microsoft Intune.
The Intune Administrator role contains the ability to manage users and devices in order to associate policies, as well as creating and managing all security groups in Azure AD.
Important Note
Intune Administrator does not have admin rights over Office groups.
Domain Administrator
Users with this role will be able to create computer accounts in your on-premises domain. This is needed...