New Feature: Role-based access controls for Windows Autopatch
Windows Autopatch introduces role-based access controls for update management, available from May 27, 2025. New roles include Windows Autopatch Administrator and Reader. Custom roles and Intune scope tags are supported. Review and update permissions for users in deprecated Modern Workplace Roles. For assistance, visit the Microsoft Intune admin center. Windows Autopatch will now provide role-based access controls to access key update management features, previously limited to Intune Service administrators. With this change, administrators can assign specific roles and permissions, so that only authorized personnel can perform update management actions and read reports. With this change you will be able to grant appropriate access rights to individuals, resulting in far fewer privileges for update management, therefore minimizing the need for Intune Service administrator privileges. When will this happen: General Availability will take place starting May 27, 2025, Pacific Standard Time, and the change will be completed in 4 weeks. How will this affect your organization: This release includes the following Built-in roles Windows Autopatch Administrator: This includes full permissions necessary for Autopatch Groups, Autopatch reports and Messages. Windows Autopatch Reader: This includes read permissions necessary for Autopatch Groups, Autopatch reports and Messages but does not permit any changes. IT admins have been using the Intune role Policy and Profile Manager or an Intune custom role with equivalent permissions that include Device configuration permissions for managing Intune policies. To fully access advanced update management features such as Autopatch Groups, a user must be assigned to both Policy and Profile Manager and Windows Autopatch administrator. The roles will be available at Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles Custom roles – you can create a custom Autopatch role and include just the permissions required for update related activities. You can access this from Microsoft Intune admin center -> Tenant Administration -> Roles -> All roles -> Create -> Windows Autopatch role. You will be able to assign Intune scope tags to Autopatch Groups and filter Autopatch reports based on scope tags. Windows Autopatch reports – You will be able to access the Windows Autopatch reports with the above […]
The post New Feature: Role-based access controls for Windows Autopatch appeared first on M365 Admin.
Published on:
Learn moreWe can help you with New Feature: Role-based access controls for Windows Autopatch
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Purview: Auto-labeling scalability, policy management, and reporting enhancements
Microsoft Purview is improving auto-labeling capabilities to help organizations manage and validate labeling policies at enterprise scale. The...
Updates available for Microsoft 365 Apps for all channels
We’ve released updates to the following update channels for Microsoft 365 Apps: Current Channel Monthly Enterprise Channel Semi-Annual E...
Microsoft Purview | Data Lifecycle Management – Graph API Support for archive mailboxes
Microsoft is retiring Exchange Web Services (EWS) in Exchange Online by April 2027 and expanding Microsoft Graph API support for archive mailb...
[Whiteboard] Legacy Whiteboard migration to OneDrive
Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...
Microsoft Publisher: Reminder that support ends in October 2026
Microsoft Publisher support ends October 1, 2026; it will no longer be available in Microsoft 365 subscriptions. Users should convert or migra...
[Whiteboard] Standalone app deprecation (Windows, Mobile)
Microsoft will retire standalone Whiteboard apps for Windows, iOS, and Android on October 16, 2026. Users must switch to accessing Whiteboard ...
Microsoft Entra: Optimized passkey registration campaign experience
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoptio...
The September 2026 Scan Cab is available
IMPORTANT: This notice only affects environments where Scan Cab is used to check for update compliance. What and why: The September 2026 Scan ...
Teams admin center device state rules and health alerts retire; use Teams Rooms Pro Management portal
Teams admin center’s device state rules and health alerts will retire by late September 2026. Device health monitoring moves to the Team...
Build apps in Microsoft Copilot Studio and Copilot Cowork
Microsoft announces a preview of app-building in Copilot Cowork starting September 8, 2026, with Copilot Studio following soon. Users with lic...