Intune Administrator
Attack path
An Intune Administrator can deploy scripts, applications and configuration profiles to managed endpoints and may be able to retrieve recovery information such as BitLocker keys. An attacker could target an administrator's managed workstation with a malicious deployment, then capture credentials or hijack an authenticated session from that device. Successful execution on a privileged access workstation could turn endpoint-management rights into an Entra identity compromise, although the path depends on the target device being enrolled and within the attacker's administrative scope.
Description
Can manage all aspects of the Intune product.
Details
Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups.
Directory Actions38
| Action | Condition |
|---|---|
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.cloudPC/allEntities/allProperties/allTasks | null |
microsoft.directory/bitlockerKeys/key/read | null |
microsoft.directory/contacts/basic/update | null |
microsoft.directory/contacts/create | null |
microsoft.directory/contacts/delete | null |
microsoft.directory/deletedItems.devices/delete | null |
microsoft.directory/deletedItems.devices/restore | null |
microsoft.directory/deviceLocalCredentials/password/read | null |
microsoft.directory/deviceManagementPolicies/standard/read | null |
microsoft.directory/deviceRegistrationPolicy/standard/read | null |
microsoft.directory/devices/basic/update | null |
microsoft.directory/devices/create | null |
microsoft.directory/devices/delete | null |
microsoft.directory/devices/disable | null |
microsoft.directory/devices/enable | null |
microsoft.directory/devices/extensionAttributeSet1/update | null |
microsoft.directory/devices/extensionAttributeSet2/update | null |
microsoft.directory/devices/extensionAttributeSet3/update | null |
microsoft.directory/devices/registeredOwners/update | null |
microsoft.directory/devices/registeredUsers/update | null |
microsoft.directory/groups/hiddenMembers/read | null |
microsoft.directory/groups.security/assignedLabels/update | null |
microsoft.directory/groups.security/basic/update | null |
microsoft.directory/groups.security/classification/update | null |
microsoft.directory/groups.security/create | null |
microsoft.directory/groups.security/delete | null |
microsoft.directory/groups.security/dynamicMembershipRule/update | null |
microsoft.directory/groups.security/members/update | null |
microsoft.directory/groups.security/owners/update | null |
microsoft.directory/groups.security/visibility/update | null |
microsoft.directory/users/basic/update | null |
microsoft.directory/users/manager/update | null |
microsoft.directory/users/photo/update | null |
microsoft.intune/allEntities/allTasks | null |
microsoft.office365.organizationalMessages/allEntities/allProperties/read | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions56
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
BitlockerKey.ReadBasic.AllCloudPC.Read.AllCloudPC.ReadWrite.AllDevice.CreateFromOwnedTemplateDevice.Read.AllDeviceLocalCredential.ReadBasic.AllDeviceManagementApps.Read.AllDeviceManagementApps.ReadWrite.AllDeviceManagementConfiguration.Read.AllDeviceManagementConfiguration.ReadWrite.AllDeviceManagementManagedDevices.Read.AllDeviceManagementManagedDevices.ReadWrite.AllDeviceManagementRBAC.Read.AllDeviceManagementRBAC.ReadWrite.AllDeviceManagementScripts.Read.AllDeviceManagementScripts.ReadWrite.AllDeviceManagementServiceConfig.Read.AllDeviceManagementServiceConfig.ReadWrite.AllDeviceTemplate.Read.AllDeviceTemplate.ReadWrite.AllDirectory.Read.AllGroup.Read.AllGroup.ReadWrite.AllGroupMember.Read.AllGroupMember.ReadWrite.AllGroupSettings.Read.AllLicenseAssignment.Read.AllLicenseAssignment.ReadWrite.AllOrgContact.Read.AllPolicy.Read.AllPolicy.Read.DeviceConfigurationRoleManagement.Read.CloudPCRoleManagement.ReadWrite.CloudPCSignInIdentifier.Read.AllSignInIdentifier.ReadWrite.AllUser-ConvertToInternal.ReadWrite.AllUser-LifeCycleInfo.Read.AllUser-LifeCycleInfo.ReadWrite.AllUser-Mail.ReadWrite.AllUser-OnPremisesSyncBehavior.ReadWrite.AllUser-PasswordProfile.ReadWrite.AllUser.CreateUser.DeleteRestore.AllUser.EnableDisableAccount.AllUser.Export.AllUser.Invite.AllUser.ManageIdentities.AllUser.Read.AllUser.ReadBasic.AllUser.ReadWrite.AllUser.RevokeSessions.AllUserAuthenticationMethod.Read.AllUserAuthenticationMethod.ReadWrite.AllUserAuthMethod-External.ReadWrite.AllUserAuthMethod-HardwareOATH.ReadWrite.AllUserAuthMethod-TAP.ReadWrite.All