New Feature: Role-based access controls for Windows Autopatch
Windows Autopatch introduces role-based access controls for update management, available from May 27, 2025. New roles include Windows Autopatch Administrator and Reader. Custom roles and Intune scope tags are supported. Review and update permissions for users in deprecated Modern Workplace Roles. For assistance, visit the Microsoft Intune admin center. Windows Autopatch will now provide role-based access controls to access key update management features, previously limited to Intune Service administrators. With this change, administrators can assign specific roles and permissions, so that only authorized personnel can perform update management actions and read reports. With this change you will be able to grant appropriate access rights to individuals, resulting in far fewer privileges for update management, therefore minimizing the need for Intune Service administrator privileges. When will this happen: General Availability will take place starting May 27, 2025, Pacific Standard Time, and the change will be completed in 4 weeks. How will this affect your organization: This release includes the following Built-in roles Windows Autopatch Administrator: This includes full permissions necessary for Autopatch Groups, Autopatch reports and Messages. Windows Autopatch Reader: This includes read permissions necessary for Autopatch Groups, Autopatch reports and Messages but does not permit any changes. IT admins have been using the Intune role Policy and Profile Manager or an Intune custom role with equivalent permissions that include Device configuration permissions for managing Intune policies. To fully access advanced update management features such as Autopatch Groups, a user must be assigned to both Policy and Profile Manager and Windows Autopatch administrator. The roles will be available at Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles Custom roles – you can create a custom Autopatch role and include just the permissions required for update related activities. You can access this from Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles -> Create -> Windows Autopatch role. You will be able to assign Intune scope tags to Autopatch Groups and filter Autopatch reports based on scope tags. Windows Autopatch reports – You will be able to access the Windows Autopatch reports with the above […]
The post New Feature: Role-based access controls for Windows Autopatch appeared first on M365 Admin.
Published on:
Learn moreWe can help you with New Feature: Role-based access controls for Windows Autopatch
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Copilot (Microsoft 365): Local inferencing
Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...
Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria
Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...
Microsoft Viva: Ability for leaders to publish Power BI reports
Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...
Dynamics 365 Customer Service: Detailed quality evaluation score breakdown
Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...
Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria
Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...
Dynamics 365 Customer Service: Inactivate quality evaluation records
Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...
Microsoft Teams: Granular Conditional Access for Teams meetings
Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...
Customized PowerBI reports behavior after major report updates
Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...
Microsoft SharePoint: Changes to the FAQ web part authoring experience
The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...
Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...