nerdexam
Microsoft

MD-102 · Question #477

You have a Microsoft 365 E5 subscription that includes Microsoft Intune and contains a user named Admin1. Admin1 must use the Microsoft Intune admin center to perform the following tasks: - Create…

The correct answer is E. Create a custom Intune role and assign the role to Admin1. Admin1 needs two distinct capability sets: standard Intune management (create/assign apps and policies) and Windows 365 Cloud PC provisioning policy management (create, assign, delete). No single built-in role covers both with least privilege - Cloud PC Administrator (C) covers…

Submitted by takeshi77· Apr 18, 2026Manage and maintain devices

Question

You have a Microsoft 365 E5 subscription that includes Microsoft Intune and contains a user named Admin1. Admin1 must use the Microsoft Intune admin center to perform the following tasks:

  • Create and assign apps and policies to users and devices by using

Intune.

  • Create, assign, and delete Windows 365 Cloud PC provisioning

policies. You need to assign the required roles to Admin1. The solution must meet the following requirements:

  • Follow the principle of least privilege.
  • Minimize administrative effort.

What should you do?

Options

  • AAssign Admin1 the Help Desk Operator role.
  • BAssign Admin1 the Cloud PC Reader role.
  • CAssign Admin1 the Cloud PC Administrator role.
  • DCreate a custom Microsoft Entra role and assign the role to Admin1.
  • ECreate a custom Intune role and assign the role to Admin1.

How the community answered

(53 responses)
  • A
    21% (11)
  • B
    2% (1)
  • C
    4% (2)
  • D
    9% (5)
  • E
    64% (34)

Explanation

Admin1 needs two distinct capability sets: standard Intune management (create/assign apps and policies) and Windows 365 Cloud PC provisioning policy management (create, assign, delete). No single built-in role covers both with least privilege - Cloud PC Administrator (C) covers Windows 365 but grants excessive rights beyond provisioning policies, and does not include standard Intune management. Creating a custom Intune role (E) allows precise scoping of exactly the Intune app/policy permissions and Windows 365 provisioning policy permissions required, satisfying the principle of least privilege while combining both needs into a single role assignment to minimize administrative effort.

Topics

#Intune RBAC#Custom roles#Windows 365 Cloud PC#Least privilege

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice