Role permission on Entra / Intune

Consultant Djelal Kasamoski 0 Reputation points
2025-11-12T15:18:24.69+00:00

Hi Guys,
i have created a role-based access control for a User to allow him to see Bitlocker Key.
Currently the user is managing devices from Intune, but i noticed after the creation of the role he can see all the devices on Entra.
Is it possible to block the access to Entra and leave just Intune or something else to restrict access on after logging to Entra to the same device and user that he can manage from Intune?

Thanks

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
{count} votes

1 answer

Sort by: Most helpful
  1. Rukmini 8,600 Reputation points Microsoft External Staff Moderator
    2025-11-19T12:00:55.75+00:00

    Hello Consultant Djelal Kasamoski,

    No, without granting access to every device in Entra, you cannot permit a user to view BitLocker keys in Intune.

    • Tenant-wide accessibility to all devices is automatically granted by any Entra role that has device.read rights; this cannot be scoped.

    To limit access so that the user can only view the devices under their control:

    • Eliminate the Entra role and replace it with Intune RBAC.
    • Create a custom Intune role and scope it to a group of devices using the BitLocker key read.

    In this way, the user won't see every device in Entra and can only view BitLocker keys for particular Intune devices.


    If the resolution was helpful, kindly take a moment to accept the answer and upvote it 👍 it as a token of appreciation.

    2 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.