Multi admin approval
For PowerShell scripts, you can also leverage a multi admin approval workflow in Microsoft Intune so that an IT admin cannot deploy PowerShell scripts to devices without another IT admin having approved it:
- In the Microsoft Intune admin center, browse to Home | Tenant administration | Multi Admin Approval | Access policies and click Create:
Figure 10.61: Multi Admin Approval
- Then you need to give the access policy a name and keep the default profile type as Script.
- A script policy will limit actions on a script, such as PowerShell scripts or remediation scripts. These could include create, edit, assign, and delete.
- You need to select a group of approvers:
Figure 10.62: Multi Admin Approval Approvers
When you create a new PowerShell script, you do not have the Assign step in the workflow but you will need to add a business justification:
Figure 10.63: Business justification
In the Multi...