📄️ DEV-116 - Configure Privileged Roles for Intune Admins (PIM, CA, etc)
Implementation Effort: Medium – Requires planning and configuration of Conditional Access policies specifically targeting admin roles.
📄️ DEV-118 - RBAC
Implementation Effort: Medium – Requires role design, assignment planning, and ongoing maintenance of custom roles.
📄️ DEV-119 - Multi-Admin Approval
Implementation Effort: Medium – Requires enabling the feature and defining approval policies with designated approvers.
📄️ DEV-120 - Scope Groups
Implementation Effort: Medium – Requires planning of group structure aligned to organizational boundaries and ongoing group membership management.
📄️ DEV-121 - Scope Tags
Implementation Effort: Medium – Requires defining a tagging taxonomy, applying tags to all relevant objects, and maintaining consistency as new policies are created.
📄️ DEV-122 - Require SAW for Admin Actions
Implementation Effort: High – Requires procuring and provisioning dedicated Secure Admin Workstations, defining Conditional Access policies, and changing admin workflows.
📄️ 001: Filters
Implementation Effort: Low – IT and Security Operations teams need to create new filters as smarter grouping and targetting method.
📄️ 002: Device groups
Implementation Effort: Low – IT and Security Operations teams need to create new devices groups.
📄️ 003: User groups
Implementation Effort: Low – IT and Security Operations teams need to create new user groups.
📄️ 004: Scope Tags
Implementation Effort: Medium – IT and Security Operations teams need scope tags and assign them to users and devices.
📄️ 005: Scope Groups
Implementation Effort: Medium – IT and Security Operations teams may need to create new users and devices groups to be used for RBAC controls.
📄️ 006: Organizational Messages
Overview