Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Microsoft Intune RBAC controls who can run remote device actions and which managed devices they can target. For a quick deployment, assign the built-in Help Desk Operator role. For least privilege, create a custom Intune role with only the required Remote tasks/<action> permission, plus the read permissions and assignment scope needed to see and access the target devices.

This is separate from Remote Help, which provides interactive screen viewing, control, and elevation. Sync, Restart, Collect diagnostics, Retire, Wipe, and similar operations are ordinary Intune device actions and do not automatically require Remote Help.

What Intune RBAC controls

Intune role-based access control determines four things:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Which administrative operations a user can perform.
  • Which devices or users the administrator can see and manage.
  • Whether a particular remote action is available.
  • Which administrative scope limits the assignment.

A remote-action permission by itself may not be enough. The operator generally also needs visibility of the device, such as Managed devices/Read and, depending on the action, Organization/Read. The device must also be included in the assignment’s scope group.

Remote device actions are not Remote Help

Intune remote device actions are administrative commands sent to managed devices. The current action catalog includes operations such as Sync, Restart, Retire, Wipe, Delete, Rename, Collect diagnostics, Autopilot Reset, BitLocker key rotation, Remote lock, Locate device, and Send custom notification. The available actions depend on the device platform, ownership, enrollment type, connectivity, and policy.

Remote Help is a different product capability. It is designed for an interactive support session. Its permissions include:

  • Remote Help - View screen
  • Remote Help - Take full control
  • Remote Help - Elevation
  • Remote Help - Unattended
  • Remote Tasks - Offer remote assistance
  • Remote Assistance Connector - Read

Microsoft’s Remote Help planning documentation explains that helpers generally need the relevant Remote Help permission together with permission to offer remote assistance and read the connector. Granting Remote tasks/Restart or Remote tasks/Collect diagnostics does not provide interactive control of a user’s screen.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right role

Built-in Help Desk Operator

The built-in Help Desk Operator role is the fastest supported option for a conventional support team. It is maintained by Microsoft and is suitable when the help desk already needs a broad set of device and user troubleshooting capabilities.

Its trade-off is scope: it may grant more permissions than a Tier-1 team needs. Do not interpret it as a guarantee that every action will appear for every device. Platform support, enrollment type, device scope, check-in status, and approval policies still apply.

Use it for small teams, temporary troubleshooting access, or environments where the help desk’s responsibilities are intentionally broad.

Custom Intune role

Create a custom role when you need separation between Tier-1 and Tier-2 support, Windows and mobile support, troubleshooting and destructive operations, or regional and business-unit teams. A custom role also makes it easier to prohibit Wipe, Delete, Retire, and recovery-key operations from routine support accounts.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create a custom role for remote actions

Portal labels can change with the Intune admin center interface or localization, but the current workflow is:

  1. Sign in to the Microsoft Intune admin center.
  2. Go to Tenant administration > Roles.
  3. Select All roles, then select Create.
  4. Choose Intune role.
  5. Enter a descriptive name and purpose, such as Tier 1 – Non-destructive device actions.
  6. On Permissions, expand Remote tasks.
  7. Set only the required action to Yes.
  8. Add the read permissions required to identify and access the devices.
  9. Finish creating the role.
  10. Open the role and create a role assignment.
  11. Select the administrative group: the users or groups who receive the role.
  12. Select assignment scope groups containing the target users or devices.
  13. Review exclusions, if any, and save the assignment.
  14. Test with a non-administrator pilot account.

Microsoft’s Collect diagnostics guidance illustrates the important pattern: the action permission is combined with visibility permissions such as Organization/Read and Managed devices/Read.

Permission examples by action

There is no universal permission list that applies identically to every action. Check the exact permission label displayed in your tenant and confirm the current Microsoft Learn page for the target platform.

Use case Action permission to investigate Other requirements to verify
Collect diagnostics Remote tasks/Collect diagnostics Organization/Read, Managed devices/Read, supported platform, connectivity
Retire a device Remote tasks/Retire Device visibility, supported enrollment type, and possible Multiple Administrative Approval
Remote Help Remote Tasks/Offer remote assistance Remote Assistance Connector - Read and the required Remote Help capability
Retrieve a macOS FileVault key Remote tasks/Get FileVault key Device visibility, supported corporate-owned macOS state, and an escrowed key
Rotate a macOS FileVault key Remote tasks/Rotate FileVault key Device visibility and supported FileVault configuration
Rotate BitLocker keys Remote tasks/Rotate BitLockerKeys Supported Windows configuration and device access
Sync a device Remote tasks/Sync devices Device visibility and a reachable Intune-managed device
Restart or reboot Remote tasks/Reboot now or the tenant’s current restart label Supported platform, connectivity, and user-impact review
Wipe a device Action-specific wipe permission Device visibility, platform support, enrollment support, and destructive-action governance

Permission names and capitalization can change. Treat the labels above as examples to investigate, not as a substitute for checking the current role editor and action documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended least-privilege role designs

Tier-1 troubleshooting

Consider granting organization and managed-device read access together with Sync, Collect diagnostics, Send custom notification, and Restart if the operational impact is acceptable. Exclude Wipe, Delete, Retire, Autopilot Reset, Fresh Start, FileVault-key retrieval, BitLocker-key rotation, and Locate device unless there is a documented need.

Tier-2 endpoint support

Add carefully selected operations such as Remote lock, Rename, BitLocker key rotation, or FileVault-key retrieval. Recovery keys are sensitive credentials and should be protected with a smaller operator group, stronger authentication, and regular audit review.

Recovery and offboarding

Use a separately governed role for Retire, Wipe, Delete, Autopilot Reset, and Fresh Start. Require a ticket, approval, or privileged-access workflow where possible. Do not bundle destructive actions into a general help-desk role simply because the team also needs Sync or diagnostics.

Remote Help

Assign screen viewing, full control, elevation, unattended support, offer-remote-assistance, and connector permissions independently. Microsoft recommends Conditional Access for helper accounts because Remote Help can provide elevated access into user devices. Review the Remote Help deployment guidance before enabling sessions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Admin group, scope group, permissions, and exclusions

Assignment element Meaning
Admin group The users or groups who receive the role.
Permission set The operations those administrators may perform.
Scope groups The users or devices those operations can target.
Exclusions Users or devices removed from the assignment’s effective scope.

A correctly configured role can still fail if the target device is outside the scope group or an exclusion overrides the expected assignment. The same principle applies to Remote Help: Microsoft notes that the device or session participant must be within the helper’s scope.

Platform and connectivity limitations

Remote actions are not universal commands. Before granting or testing one, verify the device’s operating system, ownership, enrollment model, management state, and last check-in.

  • The device must be enrolled and in a supported management state.
  • The platform and enrollment type must support the selected action.
  • The device generally must be online and able to communicate with Intune to receive the command.
  • A stale check-in, unavailable push service, or network restriction can delay execution.
  • Some actions require a specific ownership state, such as corporate-owned iOS/iPadOS.
  • Another pending destructive action may block or conflict with the command.
  • A tenant access policy may require Multiple Administrative Approval.

For Collect diagnostics, Microsoft currently documents support for Android and iOS/iPadOS through app protection, corporate-owned Windows devices, and Windows Holographic. The documentation also states that collection can target up to 25 devices at a time. That limit is specific to the current diagnostics workflow; it should not be assumed for every remote action. Diagnostic data is stored in Microsoft support systems and is not governed by Intune data-management policies or protections. Review the current prerequisites and regional endpoint requirements before restricting network access.

Retire versus Delete versus Wipe

Action Typical effect Operational warning
Retire Removes company data and management settings while generally preserving personal data. The command may not take effect until the device checks in.
Delete Removes the Intune device object; Microsoft documents it as triggering Retire for Windows, Apple, and macOS, while behavior varies for Android enrollment types. Confirm the platform and enrollment model before using it. See Microsoft’s Delete documentation.
Wipe Resets the device to factory settings and removes data and settings, subject to platform-specific options. Treat it as destructive and require explicit governance.

Microsoft’s Retire documentation lists support for Android device administrator, Android Enterprise personally owned work profile, iOS/iPadOS, macOS, and Windows, and identifies Remote tasks/Retire as the custom-role permission. An Intune access policy may require Multiple Administrative Approval.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Safe testing and rollback

  1. Create a pilot admin group and a pilot device scope group.
  2. Start with a non-destructive action such as Sync, Send custom notification, or Collect diagnostics.
  3. Confirm the operator can find the device and see the expected action.
  4. Run the command against a test device that is online and recently checked in.
  5. Record the command result, device check-in time, and ticket reference.
  6. Review Intune audit logs for the assignment and action.
  7. Test a negative case: confirm the operator cannot target a device outside the scope.
  8. Remove any temporary Help Desk Operator assignment after comparing it with the custom role.

For production, use separate groups for routine support and recovery operations. Review assignments periodically and remove inactive accounts, contractors, and temporary access.

Troubleshooting missing or failed actions

The user has Help Desk Operator but cannot see the device

  • Confirm the role assignment applies to the signed-in user.
  • Confirm the user is in the assignment’s administrative group.
  • Confirm the device is in the assignment’s scope group.
  • Check group exclusions.
  • Confirm the device is enrolled and represented by the expected Intune record.

The action is visible but fails

  • Check whether the device is online and has checked in recently.
  • Verify platform and enrollment support.
  • Look for a stale or inconsistent device record.
  • Check for another pending or conflicting action.
  • Verify additional action-specific permissions and any approval policy.

Collect diagnostics is unavailable

Check Remote tasks/Collect diagnostics, Managed devices/Read, and Organization/Read. Then verify corporate ownership for Windows, supported platform status, device connectivity, and network access to the appropriate regional Microsoft diagnostics storage endpoint.

The button remains missing in a custom role

Temporarily test the same pilot user and device with Help Desk Operator. If the built-in role works, compare the custom role’s exact Remote tasks permission, read permissions, scope groups, exclusions, and assignment membership. Remove the broad test role when finished.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Intune RBAC versus Microsoft Graph permissions

Portal RBAC and Microsoft Graph authorization are separate. A user authorized to run an action interactively in the Intune admin center does not automatically receive arbitrary Graph access. An automation account or application calling Graph requires its own delegated or application permissions, consent, and authorization design. Do not infer Graph access from an Intune portal role assignment.

For cloud-attached or tenant-attached devices, also validate the authority and configuration of the hybrid environment. Microsoft documents relevant considerations in its Intune RBAC guidance for Configuration Manager cloud-attached devices.

Security recommendations

  • Use custom roles for narrowly defined help-desk tasks.
  • Keep Wipe, Delete, Retire, Autopilot Reset, and Fresh Start out of routine Tier-1 roles.
  • Protect BitLocker and FileVault key permissions as sensitive access.
  • Require MFA and use Conditional Access for privileged support accounts.
  • Use just-in-time or approval-based elevation, such as Privileged Identity Management where available.
  • Limit assignments with administrative scope groups and exclusions.
  • Require ticket references or approvals for destructive actions.
  • Monitor Intune audit logs and review role assignments regularly.
  • For interactive support, govern Remote Help separately from ordinary device actions.

Licensing and product boundaries

Native Intune remote actions are part of device-management workflows; they do not inherently require an interactive remote-control product. Intune licensing depends on the organization’s plan and agreement.

Remote Help and the Intune Suite are relevant when support staff need screen viewing, full control, elevation, or eligible unattended support. Treat Remote Help as a separately licensed add-on or suite capability, with its own deployment and security requirements. TeamViewer integration may suit organizations that already standardize on that platform or need an external remote-control provider, but it is not required merely to run Sync, Restart, Retire, Wipe, or Collect diagnostics. Licensing, availability, and pricing vary by geography, date, and agreement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Conclusion

The safest Intune design is to separate what an operator can do from which devices the operator can reach. Start with Help Desk Operator only when its broad permissions are acceptable. Otherwise, create a custom role containing the exact Remote tasks/<action> permission, the necessary read access, and a tightly controlled scope group. Test with non-destructive actions, audit the result, and govern destructive operations separately.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.