Skip to content

Commit 11bdb53

Browse files
Merge pull request #19198 from MicrosoftDocs/main
[AutoPublish] main to live - 11/21 13:30 PST | 11/22 03:00 IST
2 parents 50e2110 + dbf6b5b commit 11bdb53

File tree

97 files changed

+726
-794
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

97 files changed

+726
-794
lines changed

intune/agents/change-review-agent.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -73,10 +73,10 @@ The agent analyzes these signals to assess the potential risk associated with ea
7373
:::row-end:::
7474
<!-- end plugin -->
7575

76-
<!-- start platform ../../media/icons/admin-center/devices.svg -->
76+
<!-- start platform ../../media/icons/16/devices.svg -->
7777
:::row:::
7878
:::column span="1":::
79-
:::image type="icon" source="../media/icons/admin-center/devices.svg" border="false"::: **Platform requirements and scenarios**
79+
:::image type="icon" source="../media/icons/16/devices.svg" border="false"::: **Platform requirements and scenarios**
8080
:::column-end:::
8181
:::column span="3":::
8282
> The agent supports evaluation and recommendations for the following platforms and scenarios:
@@ -99,12 +99,12 @@ The agent analyzes these signals to assess the potential risk associated with ea
9999
>
100100
> To **enable and configure** the Change Review Agent, use an account with the following roles:
101101
>
102-
> :::image type="icon" source="../media/icons/admin-center/entra.svg" border="false"::: Entra roles:
102+
> :::image type="icon" source="../media/icons/16/entra.svg" border="false"::: Entra roles:
103103
> - [*Intune Administrator*](/entra/identity/role-based-access-control/permissions-reference#intune-administrator)
104104
> - [*Security Reader*](/entra/identity/role-based-access-control/permissions-reference#security-reader)
105105
> - *Entra/Identity risky user (read)* - This permission maps to the Unified RBAC permission *Security posture / Identity risk / Risky users (read)*.
106106
>
107-
> :::image type="icon" source="../media/icons/admin-center/defender.svg" border="false"::: Defender roles - Defender role-based access control (RBAC) roles depend on your Defender XDR implementation:
107+
> :::image type="icon" source="../media/icons/16/defender.svg" border="false"::: Defender roles - Defender role-based access control (RBAC) roles depend on your Defender XDR implementation:
108108
> - [*Unified RBAC*](/defender-xdr/manage-rbac): Assign the Microsoft Entra ID Security Reader to the agent's identity account. This role provides read-only access to Defender Vulnerability Management data and automatically enforces device group scoping.
109109
> - [*Granular RBAC*](/defender-endpoint/rbac): Assign a custom RBAC role with permissions equivalent to the Unified RBAC Security Reader role. For example:
110110
> - *View data – Defender Vulnerability Management* - This permission maps to the Unified RBAC permission *Security posture / Posture management / Vulnerability management (read)*.
@@ -113,23 +113,23 @@ The agent analyzes these signals to assess the potential risk associated with ea
113113
>
114114
> Ensure the agent's identity is scoped in Microsoft Defender to include all relevant device groups. The agent can't access or report on devices outside its assigned scope.
115115
>
116-
> :::image type="icon" source="../media/icons/admin-center/copilot.svg" border="false"::: Security Copilot roles:
116+
> :::image type="icon" source="../media/icons/16/copilot.svg" border="false"::: Security Copilot roles:
117117
> - [Copilot owner](/copilot/security/authentication#security-copilot-roles)
118118
>
119119
> ---
120120
>
121121
> To **use** the agent and perform offboarding actions, use an account with the following roles:
122122
>
123-
> :::image type="icon" source="../media/icons/admin-center/intune.svg" border="false"::: Intune roles:
123+
> :::image type="icon" source="../media/icons/16/intune.svg" border="false"::: Intune roles:
124124
> - [Read Only Operator](/intune/intune-service/fundamentals/role-based-access-control#built-in-roles) or [custom role](/intune/intune-service/fundamentals/role-based-access-control#custom-roles) with equivalent permissions.
125125
>
126-
> :::image type="icon" source="../media/icons/admin-center/entra.svg" border="false"::: Entra roles:
126+
> :::image type="icon" source="../media/icons/16/entra.svg" border="false"::: Entra roles:
127127
> - [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader)
128128
>
129-
> :::image type="icon" source="../media/icons/admin-center/defender.svg" border="false"::: Defender roles
129+
> :::image type="icon" source="../media/icons/16/defender.svg" border="false"::: Defender roles
130130
> - Use of the agent requires the same access as *enabling and configuring* the agent.
131131
>
132-
> :::image type="icon" source="../media/icons/admin-center/copilot.svg" border="false"::: Security Copilot roles:
132+
> :::image type="icon" source="../media/icons/16/copilot.svg" border="false"::: Security Copilot roles:
133133
> - [Copilot contributor](/copilot/security/authentication#security-copilot-roles)
134134
135135
:::column-end:::

intune/agents/device-offboarding-agent.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,31 +86,31 @@ The *Device Offboarding Agent* identifies stale or misaligned devices across Int
8686
>
8787
> To **enable**, **configure**, and **delete** the Device Offboarding Agent, use an account with the following roles:
8888
>
89-
> :::image type="icon" source="../media/icons/admin-center/intune.svg" border="false"::: Intune roles, either:
89+
> :::image type="icon" source="../media/icons/16/intune.svg" border="false"::: Intune roles, either:
9090
> - [Read Only Operator](/intune/intune-service/fundamentals/role-based-access-control#built-in-roles)
9191
> - [Custom role](/intune/intune-service/fundamentals/role-based-access-control#custom-roles) with **Audit data/Read** and **Organization/Read** permissions
9292
>
93-
> :::image type="icon" source="../media/icons/admin-center/entra.svg" border="false"::: Entra roles, either:
93+
> :::image type="icon" source="../media/icons/16/entra.svg" border="false"::: Entra roles, either:
9494
> - [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader)
9595
> - [Custom role](/entra/identity/role-based-access-control/custom-create) with **Microsoft.Directory/Devices/Standard/Read** permissions
9696
>
97-
> :::image type="icon" source="../media/icons/admin-center/copilot.svg" border="false"::: Security Copilot roles:
97+
> :::image type="icon" source="../media/icons/16/copilot.svg" border="false"::: Security Copilot roles:
9898
> - [Security Copilot owner](/copilot/security/authentication#security-copilot-roles)
9999
>
100100
> ---
101101
>
102102
> To **use** the agent and perform offboarding actions, use an account with at least the following roles:
103103
>
104-
> :::image type="icon" source="../media/icons/admin-center/intune.svg" border="false"::: Intune roles, either:
104+
> :::image type="icon" source="../media/icons/16/intune.svg" border="false"::: Intune roles, either:
105105
> - [Read Only Operator](/intune/intune-service/fundamentals/role-based-access-control#built-in-roles)
106106
> - [Custom role](/intune/intune-service/fundamentals/role-based-access-control#custom-roles) with **Audit data/Read** and **Organization/Read** permissions
107107
>
108-
> :::image type="icon" source="../media/icons/admin-center/entra.svg" border="false"::: Entra roles, either:
108+
> :::image type="icon" source="../media/icons/16/entra.svg" border="false"::: Entra roles, either:
109109
> - [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader)
110110
> - [Custom role](/entra/identity/role-based-access-control/custom-create) with **Microsoft.Directory/Devices/Standard/Read** permissions\
111111
> To take action from within the agent, such as to [disable devices in Entra](/entra/identity/devices/manage-stale-devices#disable-devices), you must have the **[Disable devices](/entra/identity/role-based-access-control/custom-device-permissions#enable-or-disable-devices)** permission. You don't need this permission to run or view results from the agent.
112112
>
113-
> :::image type="icon" source="../media/icons/admin-center/copilot.svg" border="false"::: Security Copilot roles:
113+
> :::image type="icon" source="../media/icons/16/copilot.svg" border="false"::: Security Copilot roles:
114114
> - [Security Copilot contributor](/copilot/security/authentication#security-copilot-roles)
115115
116116
:::column-end:::

intune/agents/icons/approval.svg

Lines changed: 9 additions & 9 deletions
Loading

intune/agents/icons/change-review-agent.svg

Lines changed: 4 additions & 4 deletions
Loading

0 commit comments

Comments
 (0)