Skip to content

Commit a161898

Browse files
author
Mandi Ohlinger
committed
global admin
1 parent 95975af commit a161898

5 files changed

Lines changed: 19 additions & 32 deletions

File tree

intune/intune-service/apps/app-protection-policies-monitor.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -9,17 +9,18 @@ ms.collection:
99
---
1010

1111
# How to Monitor App Protection Policies
12-
[!INCLUDE [azure_portal](../includes/azure_portal.md)]
1312

1413
You can monitor the status of the app protection policies that you applied to users from the Intune app protection pane in Intune. Additionally, you can find information about the users affected by app protection policies, policy compliance status, and any issues that your users might be experiencing.
1514

1615
App protection data is retained for a minimum of 90 days. Any app instances that checked in to the Intune service within the past 90 days is included in the app protection status report.
1716

18-
> [!NOTE]
19-
> When you delete an app protection policy, scoped admins no longer see app instances associated with that policy. Global admins continue to see the policy name listed as "not available."
17+
## Before you begin
2018

21-
> [!NOTE]
22-
> For iOS 16 and later devices, the **Device Name** value in all app protection reports is a generic device name. For more information, see [Apple Developer documentation](https://developer.apple.com/documentation/uikit/uidevice/1620015-name).
19+
- When you delete an app protection policy, scoped admins no longer see app instances associated with that policy. Global Administrators continue to see the policy name listed as "not available."
20+
21+
[!INCLUDE [global-admin](../includes/global-admin.md)]
22+
23+
- For iOS 16 and later devices, the **Device Name** value in all app protection reports is a generic device name. For more information, see [Apple Developer documentation](https://developer.apple.com/documentation/uikit/uidevice/1620015-name).
2324

2425
## View the **App protection status** report
2526

intune/intune-service/apps/tutorial-configure-slack-enterprise-grid.md

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -38,11 +38,6 @@ Turn on EMM for your Slack Enterprise Grid plan by following [Slack's instructio
3838

3939
Sign in to the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431) as the built-in **[Intune Administrator](/entra/identity/role-based-access-control/permissions-reference#intune-administrator)** Microsoft Entra role.
4040

41-
If you created an Intune Trial subscription, the account that created the subscription is a Microsoft Entra [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator).
42-
43-
> [!CAUTION]
44-
> [!INCLUDE [global-admin](../includes/global-admin.md)]
45-
4641
## Set up Slack for EMM on iOS devices
4742

4843
Add the iOS/iPadOS app Slack for EMM to your Intune tenant and create an app configuration policy to enable your organizations' iOS/iPadOS users to access Slack with Intune as an EMM provider.

intune/intune-service/fundamentals/deployment-plan-setup.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -95,10 +95,7 @@ The people in your organization each need a user account before they can sign in
9595

9696
As an administrator, you can add users individually or in bulk to Intune.
9797

98-
You must be a Microsoft Entra [License Administrator](/entra/identity/role-based-access-control/permissions-reference#license-administrator) or [User Administrator](/entra/identity/role-based-access-control/permissions-reference#user-administrator) to add users to Intune. If you created an Intune Trial subscription, the account that created the subscription is a Microsoft Entra [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator).
99-
100-
> [!CAUTION]
101-
> [!INCLUDE [global-admin](../includes/global-admin.md)]
98+
You must be a Microsoft Entra [License Administrator](/entra/identity/role-based-access-control/permissions-reference#license-administrator) or [User Administrator](/entra/identity/role-based-access-control/permissions-reference#user-administrator) to add users to Intune.
10299

103100
## 5 - Create groups in Intune
104101

intune/intune-service/fundamentals/microsoft-intune-service-description.md

Lines changed: 10 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
22
title: Microsoft Intune Service Description
33
description: Microsoft Intune is a cloud-based service that helps you manage Windows, iOS/iPadOS, macOS, and Android devices.
4-
author: dougeby
5-
ms.author: dougeby
6-
ms.date: 12/12/2023
4+
author: MandiOhlinger
5+
ms.author: mandia
6+
ms.date: 01/27/2026
77
ms.topic: article
88
ms.reviewer: cacamp
99
ms.collection:
@@ -22,33 +22,27 @@ Intune is a cloud-based enterprise mobility management (EMM) service that helps
2222

2323
Intune integrates closely with Microsoft Entra ID for identity and access control, and Azure Information Protection for data protection. You can also integrate it with Configuration Manager to extend your management capabilities.
2424

25-
To learn more about how you can manage devices, apps, and protect corporate data with Intune, see the [Intune documentation](../index.yml).
25+
To learn more about how you can manage devices, apps, and protect corporate data with Intune, see [Microsoft Intune securely manages identities, apps, and devices](what-is-intune.md).
2626

2727
## 30-day free trial
2828

2929
You can start to use Intune with a 30-day free trial that includes 100 user licenses. To start your free trial, [go to the Intune Sign up page](https://admin.microsoft.com/Signup/Signup.aspx?OfferId=40BE278A-DFD1-470a-9EF7-9F2596EA7FF9&dl=INTUNE_A&ali=1#0%20). If your organization has an Enterprise Agreement or equivalent volume licensing agreement, contact your Microsoft representative to set up your free trial.
3030

31-
> [!NOTE]
32-
> If your organization has a Microsoft Online Services work or school account, and you might continue with this Intune subscription in production after the trial period ends, then choose the **Sign in** option on that page and authenticate by using the Global Administrator account for your organization. This action ensures that your Intune trial links to your existing work or school account.
33-
34-
Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to the initial set up or emergency scenarios when you can't use an existing role.
35-
36-
<!--- For a list of settings that you can set up on mobile devices, see:
31+
If your organization has a Microsoft Online Services work or school account, and you might continue with this Intune subscription in production after the trial period ends, then choose the **Sign in** option on that page and authenticate by using the Microsoft Entra Global Administrator account for your organization. This action ensures that your Intune trial links to your existing work or school account.
3732

38-
- [Enrolled device management capabilities of Microsoft Intune](introduction-intune.md)
33+
[!INCLUDE [global-admin](../includes/global-admin.md)]
3934

40-
--->
4135
## Intune Onboarding benefit
4236

43-
Microsoft offers the Intune Onboarding benefit for eligible services in eligible plans. The Onboarding benefit lets you work remotely with Microsoft specialists to get your Intune environment ready for use. For more about the Onboarding benefit, see [Microsoft Intune Onboarding Benefit Description](/fasttrack/introduction).
37+
Microsoft offers the Intune Onboarding benefit for eligible services in eligible plans. The Onboarding benefit lets you work remotely with Microsoft specialists to get your Intune environment ready for use. For more about the Onboarding benefit, see [Microsoft Intune Onboarding Benefit Description](/microsoft-365/fasttrack/introduction).
4438

4539
## Learn how Intune service updates affect you
4640

4741
Because the mobile device management ecosystem changes frequently with operating system updates and mobile app releases, Microsoft updates Intune regularly. There are three ways you can learn about changes in the Intune service:
4842

4943
* [What's new in Microsoft Intune](whats-new.md). This topic is updated with the monthly service update and weekly when, for example, apps such as the Company Portal app are released.
5044

51-
* Important service updates are also announced in the [Microsoft 365 admin center](https://admin.microsoft.com/) Message Center. If you install the companion [Microsoft 365 Admin mobile app](https://support.office.com/article/Office-365-Admin-Mobile-App-e16f6421-2a1a-4142-bf9d-9846600a060a), you can receive notifications on your mobile device. Learn more about how to work with the [Microsoft 365 Message Center](/microsoft-365/admin/manage/message-center).
45+
* Important service updates are also announced in the [Microsoft 365 admin center](https://admin.microsoft.com/) Message Center. If you install the companion [Microsoft 365 Admin mobile app](/microsoft-365/admin/admin-overview/admin-mobile-app), you can receive notifications on your mobile device. Learn more about how to work with the [Microsoft 365 Message Center](/microsoft-365/admin/manage/message-center).
5246

5347
A few helpful hints:
5448

@@ -67,7 +61,7 @@ Because the mobile device management ecosystem changes frequently with operating
6761
* [Intune Customer Success Blog](https://aka.ms/IntuneCustomerSuccess)
6862

6963
> [!NOTE]
70-
> You can monitor Intune service health in the [Microsoft 365 admin center](https://admin.microsoft.com). Choose **Service Health** in the left pane. You can also use the [Microsoft 365 Admin mobile app](https://support.office.com/article/Office-365-Admin-Mobile-App-e16f6421-2a1a-4142-bf9d-9846600a060a) to view service health.
64+
> You can monitor Intune service health in the [Microsoft 365 admin center](https://admin.microsoft.com). Choose **Service Health** in the left pane. You can also use the [Microsoft 365 Admin mobile app](/microsoft-365/admin/admin-overview/admin-mobile-app) to view service health.
7165
7266
## Types of notices Microsoft provides about the Intune service
7367

@@ -81,7 +75,7 @@ To help you plan for service changes, we notify you at least 7-90 days prior to
8175

8276
- In the event of Intune service retirement, you would be notified 12 months in advance.
8377

84-
Finally, in the rare event there's any post-incident action needed to get your service back to normal or a large change that we deem potentially disruptive based on customer feedback, we will email the service administrators based on how your [Microsoft 365 communication preferences](https://support.office.com/article/Change-your-contact-preferences-for-communications-from-Microsoft-6f70de1b-a64d-4498-bfbd-be8c83a9c0fc) are set and whether you include a valid (and preferably work) email address.
78+
Finally, in the rare event there's any post-incident action needed to get your service back to normal or a large change that we deem potentially disruptive based on customer feedback, we will email the service administrators based on how your [Microsoft 365 communication preferences](/microsoft-365/admin/manage/change-address-contact-and-more) are set and whether you include a valid (and preferably work) email address.
8579

8680
## Language support
8781

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
---
22
author: MandiOhlinger
33
ms.topic: include
4-
ms.date: 08/04/2025
4+
ms.date: 01/27/2026
55
ms.author: mandia
66
---
77

88
<!-- This include file is used in articles that mention global admin. -->
99

1010
The Global Administrator built-in role is a [privileged Microsoft Entra role](/entra/identity/role-based-access-control/privileged-roles-permissions), and has more permissions than needed for Intune. To reduce risk, don't use the Global Administrator role to manage Intune.
1111

12-
Assign the least-privileged role that can complete the task. For more information on the built-in roles and what they can do, see [Role-based access control (RBAC) with Intune](../fundamentals/role-based-access-control.md) and [Built-in role permissions for Intune](../fundamentals/role-based-access-control-reference.md).
12+
Assign the least-privileged role that can complete the task. For more information on the built-in Intune roles and what they can do, see [Role-based access control (RBAC) with Intune](../fundamentals/role-based-access-control.md) and [Built-in role permissions for Intune](../fundamentals/role-based-access-control-reference.md).

0 commit comments

Comments
 (0)