Permissions required for Intune Apps
Applies to: Patch My PC Cloud
In addition to the Permissions required for Patch My PC Cloud, we also require the following permissions to onboard to Intune Apps for Cloud (Intune Apps) and access your company data:
Note
To connect with Intune, the signed-in user must have the Cloud Application Administrator or Application Administrator role to allow creation of the Enterprise app, and the Privileged Role Administrator role to approve the Graph API permissions we require. A Global Administrator can also perform both steps. The exact permission actions required are microsoft.directory/servicePrincipals/create and microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-company-admin.
You can read more about Entra ID roles at Microsoft Entra built-in roles.
Read all group memberships
Claim
GroupMember.Read.All
Description
Allows the app to read memberships and basic group properties for all groups without a signed-in user.
Permission Type
Application
Impact if revoked
Groups cannot be added through Settings | Users
You will be unable to create new Deployments or manage existing ones.
The Migration feature is unavailable.
Discovery data is not collected.
If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company.
You will see the Permissions Issue Detected warning on the Entra ID Groups tab under Settings | Users
Read all users’ full profile
Claim
User.Read.All
Description
Allows the app to read user profiles without a signed in user.
Permission Type
Application
Impact if revoked
Will display at zero, rather than retrieving the number of users shown on the MSP Customers page.
Read and write Microsoft Intune apps
Claim
DeviceManagementApps.ReadWrite.All
Description
Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a user being signed-in.
Permission Type
Application
Impact if revoked
Groups cannot be added through Settings | Users.
You will be unable to create new Deployments or edit existing ones.
The Migration feature is unavailable.
Discovery data is not collected.
If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company. When editing an App Set that contains the affected Child Company, an error appears stating you need to remove the Child Company from the App Set to save your changes. App Sets affected by this issue will also be excluded from the Sync Schedule.
Read and write Microsoft Intune configuration
Claim
DeviceManagementServiceConfig.ReadWrite.All
Description
Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.
Permission Type
Application
Impact if revoked
Deployments will fail to auto-create during a Sync Schedule. You will need to click Recreate manually each time to recreate the affected deployments.
Deployments can still be created, but ESP Profiles will be unavailable as detailed by the tooltip.
Existing deployments containing ESP Profiles will show an error when on the Configurations tab, under the ESP Profiles section, and you will be unable to save your changes without deleting the ESP Profiles.
Note
This permission is required to manage blocking apps in the Enrollment Status Page (ESP) profile directly from the PMPC Cloud Portal. This is the only feature in our solution that relies on this permission.
We understand this permission may seem broad, but Microsoft does not offer a more granular alternative for updating the blocking apps feature in ESP profiles.
If you have concerns and choose to revoke this permission from the Patch My PC Cloud Enterprise App in your Entra ID tenant, please be aware that this will impair our ability to update deployments.
See DeviceManagementServiceConfig.ReadWrite.All | Graph Permissions for more details on the Graph endpoints covered by this API permission.
Read domains
Claim
Domain.Read.All
Description
Allows the app to read all domain properties without a signed-in user.
Permission Type
Application
Impact if revoked
When you navigate to Settings | Company and click on the Domains tab, the Permissions Issue Detected message appears, giving you the option to Reconnect to Intune.
Read Microsoft Intune device configuration and policies
Claim
DeviceManagementConfiguration.Read.All
Description
Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignments to groups, without a signed-in user.
Permission Type
Application
Impact if revoked
You will be unable to create new Deployments or edit existing ones.
The Migration feature is unavailable.
Discovery data is not collected.
If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company. Also, when editing an App Set that contains the affected Child Company, an error appears stating that you need to remove the Child Company from the App Set to save any changes.
Read Microsoft Intune devices
Claim
DeviceManagementManagedDevices.Read.All
Description
Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.
Permission Type
Application
Impact if revoked
The number of devices on the Usage tab shows as N/A.
Groups cannot be added through Settings | Users.
You will be unable to create new Deployments or edit existing ones.
The Migration feature is unavailable.
Discovery data is not collected.
For MSP Parent companies, the number of devices will be missing on the companies' list for the Child companies for whom the permission is missing.
If revoked at a Child MSP Company, that company cannot be added to an App Set at the Parent Company.
Read Microsoft Intune RBAC settings
Claim
DeviceManagementRBAC.Read.All
Description
Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.
Permission Type
Application
Impact if revoked
Deployments can still be created, but Role Scope Tags will be unavailable as detailed by the tooltip.
Existing deployments containing Role Scope Tags will show an error when edited. You will need to either cancel your edit and fix the permission issue before you can edit the deployment or remove the Role Scope Tags to save your changes.
As per the Permissions requested dialog box displayed when you connect your Intune tenant:
“If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.
Accepting these permissions means that you allow this app to use your data as specified in their terms of service and privacy statement. You can change these permissions at https://myapps.microsoft.com. Show details
Does this app look suspicious? Report it here.”
You will be prompted to grant these during whenever you connect an Intune Tenant to your PMPC Cloud Portal by clicking Accept on the Permissions requested dialog box.

Last updated
Was this helpful?