For the complete documentation index, see llms.txt. This page is also available as Markdown.

Permissions required for Intune Apps

Applies to: Patch My PC Cloud

In addition to the Permissions required for Patch My PC Cloud, we also require the following permissions to onboard to Intune Apps for Cloud (Intune Apps) and access your company data:

Note

To connect with Intune, the signed-in user must have the Cloud Application Administrator or Application Administrator role to allow creation of the Enterprise app, and the Privileged Role Administrator role to approve the Graph API permissions we require. A Global Administrator can also perform both steps. The exact permission actions required are microsoft.directory/servicePrincipals/create and microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-company-admin.

You can read more about Entra ID roles at Microsoft Entra built-in roles.

Read all group memberships

Claim

GroupMember.Read.All

Description

Allows the app to read memberships and basic group properties for all groups without a signed-in user.

Permission Type

Application

Impact if revoked

  • Groups cannot be added through Settings | Users

  • You will be unable to create new Deployments or manage existing ones.

  • The Migration feature is unavailable.

  • Discovery data is not collected.

  • If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company.

  • You will see the Permissions Issue Detected warning on the Entra ID Groups tab under Settings | Users

Read all users’ full profile

Claim

User.Read.All

Description

Allows the app to read user profiles without a signed in user.

Permission Type

Application

Impact if revoked

Will display at zero, rather than retrieving the number of users shown on the MSP Customers page.

Read and write Microsoft Intune apps

Claim

DeviceManagementApps.ReadWrite.All

Description

Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a user being signed-in.

Permission Type

Application

Impact if revoked

  • Groups cannot be added through Settings | Users.

  • You will be unable to create new Deployments or edit existing ones.

  • The Migration feature is unavailable.

  • Discovery data is not collected.

  • If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company. When editing an App Set that contains the affected Child Company, an error appears stating you need to remove the Child Company from the App Set to save your changes. App Sets affected by this issue will also be excluded from the Sync Schedule.

Read and write Microsoft Intune configuration

Claim

DeviceManagementServiceConfig.ReadWrite.All

Description

Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.

Permission Type

Application

Impact if revoked

  • Deployments will fail to auto-create during a Sync Schedule. You will need to click Recreate manually each time to recreate the affected deployments.

  • Deployments can still be created, but ESP Profiles will be unavailable as detailed by the tooltip.

  • Existing deployments containing ESP Profiles will show an error when on the Configurations tab, under the ESP Profiles section, and you will be unable to save your changes without deleting the ESP Profiles.

Note

This permission is required to manage blocking apps in the Enrollment Status Page (ESP) profile directly from the PMPC Cloud Portal. This is the only feature in our solution that relies on this permission.

We understand this permission may seem broad, but Microsoft does not offer a more granular alternative for updating the blocking apps feature in ESP profiles.

If you have concerns and choose to revoke this permission from the Patch My PC Cloud Enterprise App in your Entra ID tenant, please be aware that this will impair our ability to update deployments.

See DeviceManagementServiceConfig.ReadWrite.All | Graph Permissions for more details on the Graph endpoints covered by this API permission.

Read domains

Claim

Domain.Read.All

Description

Allows the app to read all domain properties without a signed-in user.

Permission Type

Application

Impact if revoked

When you navigate to Settings | Company and click on the Domains tab, the Permissions Issue Detected message appears, giving you the option to Reconnect to Intune.

Read Microsoft Intune device configuration and policies

Claim

DeviceManagementConfiguration.Read.All

Description

Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignments to groups, without a signed-in user.

Permission Type

Application

Impact if revoked

  • You will be unable to create new Deployments or edit existing ones.

  • The Migration feature is unavailable.

  • Discovery data is not collected.

  • If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company. Also, when editing an App Set that contains the affected Child Company, an error appears stating that you need to remove the Child Company from the App Set to save any changes.

Read Microsoft Intune devices

Claim

DeviceManagementManagedDevices.Read.All

Description

Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.

Permission Type

Application

Impact if revoked

  • The number of devices on the Usage tab shows as N/A.

  • Groups cannot be added through Settings | Users.

  • You will be unable to create new Deployments or edit existing ones.

  • The Migration feature is unavailable.

  • Discovery data is not collected.

  • For MSP Parent companies, the number of devices will be missing on the companies' list for the Child companies for whom the permission is missing.

  • If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company.

Read Microsoft Intune RBAC settings

Claim

DeviceManagementRBAC.Read.All

Description

Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.

Permission Type

Application

Impact if revoked

  • Deployments can still be created, but Role Scope Tags will be unavailable as detailed by the tooltip.

  • Existing deployments containing Role Scope Tags will show an error when edited. You will need to either cancel your edit and fix the permission issue before you can edit the deployment or remove the Role Scope Tags to save your changes.

As per the Permissions requested dialog box displayed when you connect your Intune tenant:

If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.

Accepting these permissions means that you allow this app to use your data as specified in their terms of service and privacy statement. You can change these permissions at https://myapps.microsoft.com. Show details

Does this app look suspicious? Report it here.”

You will be prompted to grant these during whenever you connect an Intune Tenant to your PMPC Cloud Portal by clicking Accept on the Permissions requested dialog box.

"Permissions requested" dialog box showing which permissions we require to connect to your Intune Tenant to connect

Last updated

Was this helpful?