Loading...

New Feature: Role-based access controls for Windows Autopatch

New Feature: Role-based access controls for Windows Autopatch

Windows Autopatch introduces role-based access controls for update management, available from May 27, 2025. New roles include Windows Autopatch Administrator and Reader. Custom roles and Intune scope tags are supported. Review and update permissions for users in deprecated Modern Workplace Roles. For assistance, visit the Microsoft Intune admin center. Windows Autopatch will now provide role-based access controls to access key update management features, previously limited to Intune Service administrators. With this change, administrators can assign specific roles and permissions, so that only authorized personnel can perform update management actions and read reports. With this change you will be able to grant appropriate access rights to individuals, resulting in far fewer privileges for update management, therefore minimizing the need for Intune Service administrator privileges. When will this happen: General Availability will take place starting May 27, 2025, Pacific Standard Time, and the change will be completed in 4 weeks. How will this affect your organization: This release includes the following Built-in roles Windows Autopatch Administrator: This includes full permissions necessary for Autopatch Groups, Autopatch reports and Messages. Windows Autopatch Reader: This includes read permissions necessary for Autopatch Groups, Autopatch reports and Messages but does not permit any changes. IT admins have been using the Intune role Policy and Profile Manager or an Intune custom role with equivalent permissions that include Device configuration permissions for managing Intune policies. To fully access advanced update management features such as Autopatch Groups, a user must be assigned to both Policy and Profile Manager and Windows Autopatch administrator. The roles will be available at Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles Custom roles – you can create a custom Autopatch role and include just the permissions required for update related activities. You can access this from Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles -> Create -> Windows Autopatch role. You will be able to assign Intune scope tags to Autopatch Groups and filter Autopatch reports based on scope tags. Windows Autopatch reports – You will be able to access the Windows Autopatch reports with the above […]

The post New Feature: Role-based access controls for Windows Autopatch appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with New Feature: Role-based access controls for Windows Autopatch

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Copilot (Microsoft 365): Local inferencing

Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...

13 hours ago

Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria

Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...

13 hours ago

Microsoft Viva: Ability for leaders to publish Power BI reports

Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...

13 hours ago

Dynamics 365 Customer Service: Detailed quality evaluation score breakdown

Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...

13 hours ago

Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria

Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...

13 hours ago

Dynamics 365 Customer Service: Inactivate quality evaluation records

Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...

13 hours ago

Microsoft Teams: Granular Conditional Access for Teams meetings

Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...

13 hours ago

Customized PowerBI reports behavior after major report updates

Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...

15 hours ago

Microsoft SharePoint: Changes to the FAQ web part authoring experience

The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...

15 hours ago

Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions

Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...

15 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.