maciejrebisz.com

IT

Policies for Office-apps in Intune – setup the permission for access – Cloud First

maximios February 28, 2025

Policies for Office-apps is not new, but it is new in Microsoft Endpoint Manager admin center (MEM) – I have been asked some question from customers, not having access to the new blade inside MEM portal. This is do to many customers is starting to delegate admin and not use Global Admin for every admin that uses Microsoft services in Azure.
It is best practices only to have the access that the admin needs to perform the job, the best way to do that is not being a Global Admin in Azure. Intune administrator is a good role to have when you are managing devices in  in Microsoft Endpoint Manager.

When trying to access Policies for Office-apps and you do not have access you will receive this message, that is not the same as it is not working, but only that you do not have the necessary rights.

If you go to https://config.office.com you will receive the same message just with a recommendation on what to do about it.

Go to Azure Active Directory Admin center with a user that have the rights to assign the right role – find the user that needs the extra roles.

  1. Search for Office
  2. Select Office apps administrator

Intune administrator is not always enough, that depends on what action you need to take, with policies for Office-apps I will recommend using on of two roles:

  • Office Apps Administrator
  • Desktop Analytics Administrator

Read more about the roles permissions here: Office Apps Administrator permissions

https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#office-apps-administrator-permissions

Desktop Analytics Administrator permissions
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#desktop-analytics-administrator-permissions

You can also use but that role gives you even more right that you may or may not need:

Security Administrator
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#office-apps-administrator-permissions

Now the user has rights to Policies for Office-apps

So what if what is the different between using policies for Office-apps and ADMX based policy in Intune??

ADMX based policy for Office in Intune, is all the GPO settings that are available for Office Pro Plus, to set them it requires that the device is managed by Intune.
Then the IT admin can set both user and device policies

Policies for Office-apps is a bit different, that applies to all Windows devices that has Office Pro Plus installed when the user signs into to Office. So that means that it applies to Domain joined, Azure Active Directive joined and Workgroup  devices.
The limitations is that it is only user polices – the advantages is that you as a IT admin can set policy like default file format even for Office installation on your users private devices. In my opinion  this helps helps the end user having a better end user experience on Office Pro Plus no matter where it is installed. Use it is configure the behavior of popop for the end user or for security settings that you really mean that the end user need to have on all devices.

The next question if – who wins??

ADMX or GPO will always win, so it you have a more restrictive policy from Intune that will will over policies for Office-apps.
I did a blog post about that – take a look at my previous blogpost “How to deploy Cloud-based user policies to Office ProPlus with out a management system”

Happy testing

Read more:

Overview of the Office cloud policy service for Office 365 ProPlus

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ Change the Office 365 ProPlus update channel for devices in your organization with Intune – Cloud First › How to deploy Autopilot device fast with MDT – Cloud First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes