Skip to content

Commit

Permalink
Merge pull request #16314 from MicrosoftDocs/main
Browse files Browse the repository at this point in the history
publish main to live, 10/9/24, 10:30 AM
  • Loading branch information
rjagiewich authored Oct 9, 2024
2 parents 235de17 + 800dcd0 commit ac01861
Show file tree
Hide file tree
Showing 3 changed files with 7 additions and 13 deletions.
2 changes: 1 addition & 1 deletion memdocs/intune/fundamentals/remote-help-windows.md
Original file line number Diff line number Diff line change
Expand Up @@ -391,7 +391,7 @@ Microsoft Edge WebView2 is required to use Remote Help. If you get an error mess
## Known Issues
For remotely starting a session on the user's device, notifications that are sent to the sharer's device when a helper launches a Remote Help session fails if the Microsoft Intune Management Service isn't running.
After the user's device is restarted, there's a delay for the service to start. You can either manually wait for the service to start (30-60 seconds after restart), or manually start the service through services.msc.
After the user's device is restarted, there's a delay for the service to start. You can either manually wait for the service to start (30 minutes after restart), or manually start the service through services.msc.
For newly enrolled devices, there's a 1 hour delay before the user's device begins receiving notifications when a helper initiates a session.

## What's New for Remote Help
Expand Down
8 changes: 6 additions & 2 deletions memdocs/intune/fundamentals/role-based-access-control.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ To create, edit, or assign roles, your account must have one of the following pe

- **Global Administrator**
- **Intune Service Administrator** (also known as **Intune Administrator**)
- An Intune role with Role permissions

## Roles

Expand Down Expand Up @@ -76,6 +77,9 @@ You can create your own roles with custom permissions. For more information abou

### Microsoft Entra roles with Intune access

Microsoft recommends following the principle of least-permissions by only assigning the minimum required permissions for an administrator to perform their duties. Global Administrator and Intune Service Administrator
are [privileged roles](/entra/identity/role-based-access-control/privileged-roles-permissions) and assignment should be limited.

| Microsoft Entra role | All Intune data | Intune audit data |
| --- | :---: | :---: |
| Global Administrator | Read/write | Read/write |
Expand All @@ -101,13 +105,13 @@ A role assignment defines:
- what resources they can see
- what resources they can change.

You can assign both custom and built-in roles to your users. To be assigned an Intune role, the user must have an Intune license.
You can assign both custom and built-in roles to your users who are administrators in Intune. To be assigned an Intune role, the user must have an Intune license.
To see a role assignment, choose **Intune** > **Tenant administration** > **Roles** > **All roles** > choose a role > **Assignments** > choose an assignment. On the **Properties** page, you can edit:

- **Basics**: The assignments name and description.
- **Members**: All users in the listed Azure security groups have permission to manage the users/devices that are listed in Scope (Groups).
- **Scope (Groups)**: Scope Groups are Microsoft Entra security groups of users or devices or both for which administrators in that role assignment are limited to performing operations on. For example, deployment of a policy or application to a user or remotely locking a device. All users and devices in these Microsoft Entra security groups can be managed by the users in Members.
- **[Scope (Tags)](scope-tags.md)**: Users in Members can see the resources that have the same scope tags.
- **[Scope Tags](scope-tags.md)**: Users in Members can see the resources that have the same scope tags.

> [!NOTE]
> Scope Tags are freeform text values that an administrator defines and then adds to a Role Assignment. The scope tag added on a role controls visibility of the role itself, while the scope tag added in role assignment limits the visibility of Intune objects (such as policies and apps) or devices to only administrators in that role assignment because the role assignment contains one or more matching scope tags.
Expand Down
10 changes: 0 additions & 10 deletions windows-365/enterprise/whats-new.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,16 +55,6 @@ For more information about public preview items, see [Public preview in Windows
### Windows 365 app
-->

<!-- ########################## -->
## Week of October 7, 2024

<!-- vvvvvvvvvvvvvvvvvvvvvv -->
### Device management

#### Call redirection<!--53718424-->

Windows 365 now supports multimedia redirection call redirection. For more information, see [Use multimedia redirection](/azure/virtual-desktop/multimedia-redirection).

<!-- ########################## -->
## Week of September 30, 2024 (Service release 2409)

Expand Down

0 comments on commit ac01861

Please sign in to comment.