Identity roles and privileges for Microsoft Intune
In order to configure Microsoft Intune, you first have to make sure that you have the required privileges to do so. The first user created in your Entra tenant will automatically become the global admin, as a member of the Global Admin role. The Global Admin role has the highest privileged role in Entra and can manage all facets of Microsoft Entra ID and Microsoft services utilizing Entra identities, including Microsoft Intune. To streamline user-role design, additional roles are available to assist in delegating access. For the initial setup of Intune and certain subsequent tasks, it is advisable to utilize an account with the Global Admin role.
There are also other roles that can help you in delegating access as part of your user-role design. Some of the next steps for Intune require the Global Admin role, so we recommend using this type of account for the initial setup.
In conjunction with user and device groups, you can...