Available Permissions
Complete reference of the granular permissions you can assign to RealmJoin custom roles, grouped by area.
Overview
This page lists the granular permissions you can assign to Custom Roles, grouped by the area of RealmJoin Portal they apply to.
The definitive, always-current list is shown by the Auto-Complete in the Custom Roles editor. Because RealmJoin's feature set keeps growing, the editor may occasionally offer a permission that is newer than this page.
Permissions build on each other. A permission that shows or changes details usually also requires the matching read permission (for example, changing a setting requires being able to see it first). Where a specific prerequisite applies, it is noted in the Requires column.
A few permissions are marked Reserved. They can be selected in the editor but are not currently surfaced anywhere in the Portal, so assigning them has no effect today. They are listed here for completeness.
Settings & Administration
CanChangeTenantSettings
CanReadSettingsDetails
Modify tenant-wide settings.
CanReadOrganizationFeatures
—
View the tenant's enabled RealmJoin features.
CanEditOrganizationFeatures
CanReadOrganizationFeatures
Enable or disable RealmJoin features for the tenant.
App Management
CanReadAppTable
—
Read access to Package Management (the package list). Does not grant access to package details.
CanChangeAppAssignments
Package details access
Add or remove user/group assignments on a package.
CanSeeAppAssignmentSettings
Package details access
See the per-assignment settings of a RealmJoin Client package.
CanChangeAppAssignmentSettings
CanSeeAppAssignmentSettings
Modify the per-assignment settings of a RealmJoin Client package.
CanEditAppExpertSettings
CanSeeAppExpertSettings
Modify an app's expert settings.
CanEditAppSettings
Package details access
Modify an app's general settings.
CanEditAppAutomation
Package details access
Modify an app's automation (if/when newer store versions roll out automatically).
CanEditAppDisplayName
Package details access
Modify an app's display name.
CanEditAppTechnicalApplicationOwners
Package details access
Modify an app's Technical Application Owners in Config.
CanEnableAppUpdateGroup
Package details access
Enable or disable a package's update group.
CanUpgradeApp
Package details access
Trigger an upgrade of a package to a newer version.
CanDeleteApp
Package details access
Delete an app from Package Management. Does not remove it from the store or uninstall existing deployments.
CanSeeSoftwareSecurityVulnerabilities
—
See known security vulnerabilities for software.
CanSeeIntuneAppJson, CanSeeIntuneAppStoreJson, CanSeeRealmJoinAppJson, CanSeeRealmJoinAppStoreJson
—
See diagnostic JSON for a package in Package Store or Package Management. Only shown when Show advanced info is enabled in Settings.
Package Store
CanReadPackageStoreTable
—
Access the Package Store list. Does not grant access to details or the ability to subscribe.
CanReadPackageStoreDetails
CanReadPackageStoreTable
Inspect a package store offering. Does not grant the ability to subscribe.
Software Requests
CanRequestSoftware
—
Submit a software packaging request to RealmJoin. Combine with CanRequestSoftwarePaas or CanRequestSoftwareOrganic.
CanRequestSoftwarePaas
—
Request a package to be produced by RealmJoin and made available in the Package Store.
CanRequestSoftwareOrganic
—
Submit an "organic" package (raw, untested setup) for distribution via RealmJoin Client.
App Categories
CanReadAppCategories
—
View the tenant's Intune app categories.
CanEditAppCategories
CanReadAppCategories
Create, edit and delete Intune app categories.
Software Report
CanReadSoftwareReportDetails
CanReadSoftwareReportTable
Inspect Software Report details.
User Management
CanChangeRealmJoinUserSettings
CanSeeRealmJoinUserSettings
Add, modify or delete the RealmJoin Client settings assigned to a user.
CanReadUserSettingDetails
—
Reserved — registered but not currently surfaced in the Portal.
CanSeeUserJsonAzureAD, CanSeeUserJsonRealmJoin
CanReadUserDetails
See diagnostic JSON tabs for a user. Only shown when Show advanced info is enabled in Settings.
CanSeeUserSignIns
CanReadUserDetails
See Microsoft Entra sign-in information for a user.
Group Management
CanChangeGroupMembers
CanReadGroupDetails
Add or remove group members.
CanEditGroupDisplayName
CanReadGroupDetails
Change a group's display name.
CanDeleteGroup
CanReadGroupDetails
Delete a group.
CanSeeRealmJoinGroupSettings
CanReadGroupDetails
See the RealmJoin Client settings assigned to a group.
CanChangeRealmJoinGroupSettings
CanSeeRealmJoinGroupSettings
Add, modify or delete the RealmJoin Client settings assigned to a group.
CanReadGroupSettingDetails
—
Reserved — registered but not currently surfaced in the Portal.
CanSeeGroupJsonAzureAD, CanSeeGroupJsonRealmJoin
CanReadGroupDetails
See diagnostic JSON for a group. Only shown when Show advanced info is enabled in Settings.
CanSeeOwnGroups
—
Allow a (non-external) user to see the groups and teams they are a member of.
Device Management
Actions and operations on devices from Device Details.
CanSyncDevice
—
Trigger an Intune sync for a managed Windows device.
CanScanDevice
—
Trigger a Defender for Endpoint scan for a Windows device.
CanRequestDeviceLogs
—
Trigger collection of "Extended Logs" for a device via RealmJoin Client.
CanChangeRealmJoinPrimaryUser
—
Assign a different primary user in RealmJoin.
CanRotateIntuneManagedDeviceLocalCredentials
—
Rotate the Intune-managed local administrator (Windows LAPS) credentials of a device.
CanRotateRecoveryKeys
—
Rotate a device's disk-encryption recovery key (BitLocker on Windows, FileVault on macOS).
Device Information
Individual information panels/tabs shown on Device Details.
CanSeeDeviceHardwareInformation
—
See a device's hardware information.
CanSeeDeviceIdentifierInformation
—
See a device's identifiers.
CanSeeDeviceGroups
—
See the groups a device is a member of.
CanSeeDeviceRealmJoinInformation
—
See RealmJoin Client details for a device.
CanSeeDeviceNetworkInformation
—
See network information for a device, including Delivery Optimization data if available.
CanSeeDeviceUsers
—
See the device's logged-on user. (Without it, users who can see device details can still see the device owner.)
CanSeeDeviceAutopilotInformation
—
See a device's Autopilot information (if present).
CanSeeDeviceSoftwarePackagesInstalled
—
See the software packages installed on a device.
CanSeeWindowsDeviceUpdatesEnrollmentState
—
See a Windows device's update (Windows Update for Business) enrollment state.
CanSeeDeviceIntuneManagedLapsStatus
—
See the Intune-managed LAPS status of a device.
CanSeeDeviceExternalLinks
—
See links to Intune, Microsoft Entra, etc. for a device.
CanSeeUserAppCatalog
—
See the App Catalog tab for a Windows device.
CanEndUserSeeDeviceStorageInformation
—
Allow an end user to see storage information for their own device.
CanSeeDeviceJsonAtp, CanSeeDeviceJsonAutopilot, CanSeeDeviceJsonAzureAD, CanSeeDeviceJsonIntune, CanSeeDeviceJsonRealmJoin
—
See diagnostic JSON tabs for a device. Only shown when Show advanced info is enabled in Settings.
Device Security
CanSeeDeviceSecurityInformation
—
See a device's security state, especially device compliance.
CanSeeDeviceExtendedSecurityInformation
—
See extended security info from Defender for Endpoint (if available).
CanSeeDeviceSecurityRecommendations
—
See Microsoft Security Center recommendations for a device.
CanSeeDeviceSecurityVulnerabilities
—
See Microsoft Security Center vulnerabilities for a device.
CanSeeDeviceSecurityAlerts
—
See security alerts for a device.
CanSeeBitLockerKeys
—
View a device's BitLocker recovery keys.
CanSeeRecoveryKeys
—
View a device's disk-encryption recovery keys (BitLocker/FileVault).
Organization
CanSeeOrganizationJsonAzureAD
—
See organization diagnostic JSON. Only shown when Show advanced info is enabled in Settings.
Self Service Forms
CanReadSelfServiceFormsHistoryDetails
—
Inspect individual Self Service Forms submissions.
CanSeeSelfServiceForms
—
See the configured Self Service Forms.
Runbooks
CanSeeRunbooks
—
See the list of available runbooks (limited by object types the user can see and by Runbook Permissions). Does not allow starting jobs.
CanRunRunbooks
CanSeeRunbooks
Start runbook jobs.
CanApproveRunbookExecution
—
Approve runbook executions that require approval.
Runbook Logs
CanReadRunbookDetails
CanReadRunbookTable
Inspect a Runbook Logs item and its output.
Remediation Scripts
CanRunRemediationScripts
CanSeeRemediationScripts
Run proactive remediation scripts.
Device Health Scripts
Manage Intune remediation / device health scripts.
CanReadDeviceHealthScriptsTable
—
See the list of device health scripts.
CanReadDeviceHealthScriptsDetails
CanReadDeviceHealthScriptsTable
Inspect a device health script.
CanStageDeviceHealthScripts
—
Stage / import device health scripts.
CanAssignDeviceHealthScripts
—
Assign device health scripts to groups.
CanScheduleDeviceHealthScripts
—
Schedule device health scripts.
CanDeleteDeviceHealthScripts
—
Delete device health scripts.
Notifications
CanReadNotificationDetails
CanReadNotificationTable
Inspect a notification.
Templates
CanReadTemplateTable
—
See the list of templates.
CanReadTemplateDetails
CanReadTemplateTable
Inspect a template.
CanEditTemplate
—
Edit a template.
CanDeleteTemplate
—
Delete a template.
CanChangeTemplatePackages
—
Change the packages contained in a template.
CanChangeTemplateTokens
—
Change a template's tokens.
Changelog
The changelog is the change/version history of an object, shown as a Changelog tab on its detail page.
CanSeeChangelog
—
See the changelog (change/version history) tab on an object's detail page — labeled History on RealmJoin apps and Versions in the Package Store, and available on Device, User, Group and Organization details.
CanReadChangelogTable
—
Reserved — registered but not currently surfaced in the Portal.
CanReadChangelogDetails
—
Reserved — registered but not currently surfaced in the Portal.
Profiles
CanReadProfileTable
—
Reserved — registered but not currently surfaced in the Portal.
CanReadProfileDetails
—
Reserved — registered but not currently surfaced in the Portal.
Operations
CanReadOperationsTable
—
See the operations list. (Currently a preview feature.)
CanReadOperationsDetails
—
Reserved — registered but not currently surfaced in the Portal.
Networks & Delivery Optimization
CanReadNetworksTable
—
See the networks list. (Currently a preview feature.)
CanReadDONetworkTable
—
Reserved — registered but not currently surfaced in the Portal.
CanReadDONetworkDetails
—
Reserved — registered but not currently surfaced in the Portal.
Logs
CanReadLogsTable
—
See the audit/log list.
CanReadLogDetails
CanReadLogsTable
Inspect a log entry.
Data Export
Workplace Cloud Storage
See, upload/edit and delete the different areas of Workplace Cloud Storage.
CanReadFavoritesTable
—
View the Favorites list.
CanReadFavoritesDetails
CanReadFavoritesTable
Inspect Favorites details.
CanEditFavorites
—
Edit Favorites.
CanDeleteFavorites
—
Delete Favorites.
CanSeeOrganizationBackgroundFiles
—
View background image files.
CanUploadOrganizationBackgroundFiles
—
Upload background image files.
CanDeleteOrganizationBackgroundFiles
—
Delete background image files.
CanSeeOrganizationSignatureFiles
—
View e-mail signature files.
CanEditOrganizationSignatureFiles
—
Edit e-mail signature files.
CanDeleteOrganizationSignatureFiles
—
Delete e-mail signature files.
CanSeeOrganizationOtherFiles
—
View other organization files.
CanUploadOrganizationOtherFiles
—
Upload other organization files.
CanDeleteOrganizationOtherFiles
—
Delete other organization files.
Last updated
Was this helpful?