Delegated Administrator Permissions


Object Type NameOperation Name
MDM_GenericAppConfigurationAuthor Policy
MDM_GenericAppConfigurationCreate
MDM_GenericAppConfigurationDelete
MDM_GenericAppConfigurationDeploy Configuration Items
MDM_GenericAppConfigurationModify
MDM_GenericAppConfigurationRead
MDM_GenericAppConfigurationRun Report
MDM_GenericAppConfigurationSet Security Scope
SMS_ActionAccountResultCreate
SMS_ActionAccountResultDelete
SMS_ActionAccountResultModify
SMS_ActionAccountResultRead
SMS_AdminRead
SMS_AdminRun Report
SMS_AdvancedThreatProtectionSettingsRead
SMS_AdvancedThreatProtectionSettingsRun Report
SMS_AfwAccountStatusCreate
SMS_AfwAccountStatusDelete
SMS_AfwAccountStatusModify
SMS_AfwAccountStatusRead
SMS_AfwAppConfigSettingsAuthor Policy
SMS_AfwAppConfigSettingsCreate
SMS_AfwAppConfigSettingsDelete
SMS_AfwAppConfigSettingsDeploy Configuration Items
SMS_AfwAppConfigSettingsModify
SMS_AfwAppConfigSettingsRead
SMS_AfwAppConfigSettingsRun Report
SMS_AfwAppConfigSettingsSet Security Scope
SMS_AISoftwareListView AI
SMS_AlertCreate
SMS_AlertDelete
SMS_AlertModify
SMS_AlertRead
SMS_AlertRun Report
SMS_AllowOrDenyAppsSettingRead
SMS_AllowOrDenyAppsSettingRun Report
SMS_AntimalwareSettingsCreate
SMS_AntimalwareSettingsDelete
SMS_AntimalwareSettingsModify
SMS_AntimalwareSettingsModify Default
SMS_AntimalwareSettingsRead
SMS_AntimalwareSettingsRead Default
SMS_AntimalwareSettingsRun Report
SMS_AntimalwareSettingsSet Security Scope
SMS_AntiMalwareSettingsPolicyAuthor Policy
SMS_AntiMalwareSettingsPolicyCreate
SMS_AntiMalwareSettingsPolicyDelete
SMS_AntiMalwareSettingsPolicyModify
SMS_AntiMalwareSettingsPolicyRead
SMS_AntiMalwareSettingsPolicyRun Report
SMS_AntiMalwareSettingsPolicySet Security Scope
SMS_ApplicationApprove
SMS_ApplicationCreate
SMS_ApplicationDelete
SMS_ApplicationManage Folder
SMS_ApplicationManage Folder Item
SMS_ApplicationModify
SMS_ApplicationRead
SMS_ApplicationRun Report
SMS_ApplicationSet Security Scope
SMS_ApplicationGroupApprove
SMS_ApplicationGroupCreate
SMS_ApplicationGroupDelete
SMS_ApplicationGroupManage Folder
SMS_ApplicationGroupManage Folder Item
SMS_ApplicationGroupModify
SMS_ApplicationGroupRead
SMS_ApplicationGroupSet Security Scope
SMS_AppRestrictionSettingsAuthor Policy
SMS_AppRestrictionSettingsRead
SMS_AppRestrictionSettingsRun Report
SMS_AuthorizationListCreate
SMS_AuthorizationListDelete
SMS_AuthorizationListModify
SMS_AuthorizationListRead
SMS_BitlockerManagementSettingsAuthor Policy
SMS_BitlockerManagementSettingsRead
SMS_BitlockerManagementSettingsRun Report
SMS_BootImagePackageCreate
SMS_BootImagePackageDelete
SMS_BootImagePackageManage Folder
SMS_BootImagePackageManage Folder Item
SMS_BootImagePackageModify
SMS_BootImagePackageRead
SMS_BootImagePackageSet Security Scope
SMS_BoundaryRead
SMS_BoundaryGroupRead
SMS_ClientAuthCertificateSettingsRead
SMS_ClientAuthCertificateSettingsRun Report
SMS_ClientPfxCertificateRead
SMS_ClientSettingsCreate
SMS_ClientSettingsDelete
SMS_ClientSettingsModify
SMS_ClientSettingsRead
SMS_ClientSettingsSet Security Scope
SMS_CloudSubscriptionRead
SMS_CM_UpdatePackagesRead
SMS_CollectionAudit Security
SMS_CollectionControl AMT
SMS_CollectionCreate
SMS_CollectionDelete
SMS_CollectionDelete Resource
SMS_CollectionDeploy AntiMalware Policies
SMS_CollectionDeploy Applications
SMS_CollectionDeploy Client Settings
SMS_CollectionDeploy Configuration Items
SMS_CollectionDeploy Firewall Policies
SMS_CollectionDeploy Packages
SMS_CollectionDeploy Software Updates
SMS_CollectionDeploy Task Sequences
SMS_CollectionEnforce Security
SMS_CollectionManage Folder
SMS_CollectionManage Folder Item
SMS_CollectionModify
SMS_CollectionModify Client Status Alert
SMS_CollectionModify Collection Setting
SMS_CollectionModify Resource
SMS_CollectionNotify Resource
SMS_CollectionProvision AMT
SMS_CollectionRead
SMS_CollectionRead Resource
SMS_CollectionRemote Control
SMS_CollectionRun CMPivot
SMS_CollectionRun Script
SMS_CollectionView Collected File
SMS_CoManagementSettingsRead
SMS_CommunicationsProvisioningSettingsRead
SMS_CommunicationsProvisioningSettingsRun Report
SMS_ComplianceNotificationSettingsRead
SMS_CompliancePolicySettingsRead
SMS_ConditionAccessManagementCreate
SMS_ConditionAccessManagementDelete
SMS_ConditionAccessManagementModify
SMS_ConditionAccessManagementRead
SMS_ConditionAccessManagementSet Security Scope
SMS_ConfigurationItemCreate
SMS_ConfigurationItemDelete
SMS_ConfigurationItemManage Folder
SMS_ConfigurationItemManage Folder Item
SMS_ConfigurationItemModify
SMS_ConfigurationItemNetwork Access
SMS_ConfigurationItemRead
SMS_ConfigurationItemRun Report
SMS_ConfigurationItemSet Security Scope
SMS_ConfigurationPolicyCreate
SMS_ConfigurationPolicyDelete
SMS_ConfigurationPolicyModify
SMS_ConfigurationPolicyRead
SMS_ConfigurationPolicySet Security Scope
SMS_CustomConfigurationSettingsRead
SMS_CustomConfigurationSettingsRun Report
SMS_DeviceEnrollmentProfileCreate
SMS_DeviceEnrollmentProfileDelete
SMS_DeviceEnrollmentProfileModify
SMS_DeviceEnrollmentProfileRead
SMS_DeviceEnrollmentProfileSet Security Scope
SMS_DeviceGuardSettingsAuthor Policy
SMS_DeviceGuardSettingsRead
SMS_DeviceGuardSettingsRun Report
SMS_DeviceSettingItemCreate
SMS_DeviceSettingItemDelete
SMS_DeviceSettingItemModify
SMS_DeviceSettingItemRead
SMS_DeviceSettingItemRun Report
SMS_DeviceSettingItemSet Security Scope
SMS_DeviceSettingPackageCreate
SMS_DeviceSettingPackageDelete
SMS_DeviceSettingPackageModify
SMS_DeviceSettingPackageRead
SMS_DeviceSettingPackageSet Security Scope
SMS_DeviceThreatProtectionSettingsAuthor Policy
SMS_DeviceThreatProtectionSettingsCreate
SMS_DeviceThreatProtectionSettingsDelete
SMS_DeviceThreatProtectionSettingsModify
SMS_DeviceThreatProtectionSettingsRead
SMS_DeviceThreatProtectionSettingsRun Report
SMS_DeviceThreatProtectionSettingsSet Security Scope
SMS_DistributionPointGroupCopy to Distribution Point
SMS_DistributionPointGroupRead
SMS_DistributionPointInfoCopy to Distribution Point
SMS_DistributionPointInfoRead
SMS_DriverCreate
SMS_DriverDelete
SMS_DriverManage Folder
SMS_DriverManage Folder Item
SMS_DriverModify
SMS_DriverRead
SMS_DriverRun Report
SMS_DriverPackageCreate
SMS_DriverPackageDelete
SMS_DriverPackageManage Folder
SMS_DriverPackageManage Folder Item
SMS_DriverPackageModify
SMS_DriverPackageRead
SMS_DriverPackageSet Security Scope
SMS_EdgeBrowserSettingsRead
SMS_EditionUpgradeSettingsRead
SMS_ExploitGuardSettingsAuthor Policy
SMS_ExploitGuardSettingsCreate
SMS_ExploitGuardSettingsDelete
SMS_ExploitGuardSettingsModify
SMS_ExploitGuardSettingsRead
SMS_ExploitGuardSettingsRun Report
SMS_ExploitGuardSettingsSet Security Scope
SMS_FirewallComplianceSettingsAuthor Policy
SMS_FirewallComplianceSettingsCreate
SMS_FirewallComplianceSettingsDelete
SMS_FirewallComplianceSettingsModify
SMS_FirewallComplianceSettingsRead
SMS_FirewallComplianceSettingsRun Report
SMS_FirewallComplianceSettingsSet Security Scope
SMS_FirewallPolicyCreate
SMS_FirewallPolicyDelete
SMS_FirewallPolicyModify
SMS_FirewallPolicyRead
SMS_FirewallPolicySet Security Scope
SMS_FirewallSettingsAuthor Policy
SMS_FirewallSettingsRead
SMS_FirewallSettingsRun Report
SMS_GlobalConditionCreate
SMS_GlobalConditionDelete
SMS_GlobalConditionModify
SMS_GlobalConditionRead
SMS_GlobalConditionSet Security Scope
SMS_HealthAttestationDetailsRead
SMS_HubItemsDownload
SMS_HubItemsRead
SMS_ImagePackageCreate
SMS_ImagePackageDelete
SMS_ImagePackageManage Folder
SMS_ImagePackageManage Folder Item
SMS_ImagePackageModify
SMS_ImagePackageRead
SMS_ImagePackageSet Security Scope
SMS_InventoryReportCreate
SMS_InventoryReportDelete
SMS_InventoryReportModify
SMS_InventoryReportRead
SMS_InventoryReportRun Report
SMS_M365ASettingsAuthor Policy
SMS_M365ASettingsCreate
SMS_M365ASettingsDelete
SMS_M365ASettingsModify
SMS_M365ASettingsRead
SMS_M365ASettingsRun Report
SMS_MachineOrchestrationGroupRead
SMS_MAMPolicyTemplateCreate
SMS_MAMPolicyTemplateDelete
SMS_MAMPolicyTemplateModify
SMS_MAMPolicyTemplateRead
SMS_MAMPolicyTemplateSet Security Scope
SMS_ManagementInsightsRead
SMS_MDMAppleVppLicenseRead
SMS_MDMAppleVppTokenRead
SMS_MDMBulkEnrollmentPackagesCreate
SMS_MDMBulkEnrollmentPackagesDelete
SMS_MDMBulkEnrollmentPackagesModify
SMS_MDMBulkEnrollmentPackagesRead
SMS_MDMBulkEnrollmentPackagesSet Security Scope
SMS_MDMBulkEnrollmentProfilesCreate
SMS_MDMBulkEnrollmentProfilesDelete
SMS_MDMBulkEnrollmentProfilesModify
SMS_MDMBulkEnrollmentProfilesRead
SMS_MDMBulkEnrollmentProfilesSet Security Scope
SMS_MDMCorpEnrollmentProfilesCreate
SMS_MDMCorpEnrollmentProfilesDelete
SMS_MDMCorpEnrollmentProfilesModify
SMS_MDMCorpEnrollmentProfilesRead
SMS_MDMCorpOwnedDevicesCreate
SMS_MDMCorpOwnedDevicesDelete
SMS_MDMCorpOwnedDevicesModify
SMS_MDMCorpOwnedDevicesRead
SMS_MDMDeviceCategoryAssociate
SMS_MDMDeviceCategoryCreate
SMS_MDMDeviceCategoryDelete
SMS_MDMDeviceCategoryModify
SMS_MDMDeviceCategoryRead
SMS_MDMDeviceCategoryRun Report
SMS_MDMDeviceThreatRead
SMS_MeteredProductRuleCreate
SMS_MeteredProductRuleDelete
SMS_MeteredProductRuleManage Folder
SMS_MeteredProductRuleManage Folder Item
SMS_MeteredProductRuleModify
SMS_MeteredProductRuleModify Report
SMS_MeteredProductRuleRead
SMS_MeteredProductRuleRun Report
SMS_MeteredProductRuleSet Security Scope
SMS_ObjectContainerNodeCreate
SMS_ObjectContainerNodeDelete
SMS_ObjectContainerNodeModify
SMS_ObjectContainerNodeRead
SMS_ObjectContainerNodeSet Security Scope
SMS_OneDriveKnownFolderMigrationSettingsAuthor Policy
SMS_OneDriveKnownFolderMigrationSettingsRead
SMS_OneDriveKnownFolderMigrationSettingsRun Report
SMS_OperatingSystemInstallPackageCreate
SMS_OperatingSystemInstallPackageDelete
SMS_OperatingSystemInstallPackageManage Folder
SMS_OperatingSystemInstallPackageManage Folder Item
SMS_OperatingSystemInstallPackageModify
SMS_OperatingSystemInstallPackageRead
SMS_OperatingSystemInstallPackageSet Security Scope
SMS_PackageCreate
SMS_PackageDelete
SMS_PackageManage Folder
SMS_PackageManage Folder Item
SMS_PackageModify
SMS_PackageRead
SMS_PackageRun Report
SMS_PackageSet Security Scope
SMS_PassportForWorkProfileSettingsAuthor Policy
SMS_PassportForWorkProfileSettingsRead
SMS_PassportForWorkProfileSettingsRun Report
SMS_PfxCertificateSettingsRead
SMS_PfxCertificateSettingsRun Report
SMS_PhasedDeploymentCreate
SMS_PhasedDeploymentDelete
SMS_PhasedDeploymentModify
SMS_PhasedDeploymentRead
SMS_PolicyPropertyCreate
SMS_PolicyPropertyDelete
SMS_PolicyPropertyModify
SMS_PolicyPropertyRead
SMS_PolicyPropertySet Security Scope
SMS_QueryCreate
SMS_QueryDelete
SMS_QueryManage Folder
SMS_QueryManage Folder Item
SMS_QueryModify
SMS_QueryRead
SMS_QuerySet Security Scope
SMS_RemoteConnectionSettingsAuthor Policy
SMS_RemoteConnectionSettingsRead
SMS_RemoteConnectionSettingsRun Report
SMS_ReportCreate
SMS_ReportRead
SMS_RoleRead
SMS_ScriptsApprove
SMS_ScriptsCreate
SMS_ScriptsDelete
SMS_ScriptsManage Folder
SMS_ScriptsManage Folder Item
SMS_ScriptsModify
SMS_ScriptsRead
SMS_ScriptsSet Security Scope
SMS_SiteImport Machine
SMS_SiteManage OSD Certificate
SMS_SiteMeter Site
SMS_SiteRead
SMS_SiteRead CH Settings
SMS_SiteRun Report
SMS_SoftwareUpdateCreate
SMS_SoftwareUpdateDelete
SMS_SoftwareUpdateManage Folder
SMS_SoftwareUpdateManage Folder Item
SMS_SoftwareUpdateModify
SMS_SoftwareUpdateNetwork Access
SMS_SoftwareUpdateRead
SMS_SoftwareUpdateRun Report
SMS_SoftwareUpdatesPackageCreate
SMS_SoftwareUpdatesPackageDelete
SMS_SoftwareUpdatesPackageModify
SMS_SoftwareUpdatesPackageRead
SMS_SoftwareUpdatesPackageSet Security Scope
SMS_StateMigrationRead
SMS_StateMigrationRun Report
SMS_StatusMessageCreate
SMS_StatusMessageDelete
SMS_StatusMessageRead
SMS_StatusMessageRun Report
SMS_SubscriptionCreate
SMS_SubscriptionDelete
SMS_SubscriptionModify
SMS_SubscriptionRead
SMS_SubscriptionSet Security Scope
SMS_TaskSequencePackageCreate
SMS_TaskSequencePackageCreate Stand-alone Media
SMS_TaskSequencePackageCreate Task Sequence Media
SMS_TaskSequencePackageDelete
SMS_TaskSequencePackageManage Folder
SMS_TaskSequencePackageManage Folder Item
SMS_TaskSequencePackageModify
SMS_TaskSequencePackageRead
SMS_TaskSequencePackageRun Report
SMS_TaskSequencePackageSet Security Scope
SMS_TemplateCreate
SMS_TemplateDelete
SMS_TemplateModify
SMS_TemplateRead
SMS_TermsAndConditionsSettingsRead
SMS_TrustedRootCertificateSettingsRead
SMS_TrustedRootCertificateSettingsRun Report
SMS_UacComplianceSettingsAuthor Policy
SMS_UacComplianceSettingsCreate
SMS_UacComplianceSettingsDelete
SMS_UacComplianceSettingsModify
SMS_UacComplianceSettingsRead
SMS_UacComplianceSettingsRun Report
SMS_UacComplianceSettingsSet Security Scope
SMS_UnManagedAppsRead
SMS_UnManagedAppsRun Report
SMS_UserMachineRelationshipCreate
SMS_UserMachineRelationshipDelete
SMS_UserMachineRelationshipModify
SMS_UserMachineRelationshipRead
SMS_UserMachineRelationshipRun Report
SMS_UserStateManagementSettingsAuthor Policy
SMS_UserStateManagementSettingsRead
SMS_UserStateManagementSettingsRun Report
SMS_VhdPackageCreate
SMS_VhdPackageDelete
SMS_VhdPackageManage Folder
SMS_VhdPackageManage Folder Item
SMS_VhdPackageModify
SMS_VhdPackageRead
SMS_VhdPackageSet Security Scope
SMS_VirtualEnvironmentCreate
SMS_VirtualEnvironmentDelete
SMS_VirtualEnvironmentModify
SMS_VirtualEnvironmentRead
SMS_VirtualEnvironmentSet Security Scope
SMS_VpnConnectionSettingsAuthor Policy
SMS_VpnConnectionSettingsRead
SMS_VpnConnectionSettingsRun Report
SMS_WindowsDefenderAntimalwareSettingsAuthor Policy
SMS_WindowsDefenderAntimalwareSettingsCreate
SMS_WindowsDefenderAntimalwareSettingsDelete
SMS_WindowsDefenderAntimalwareSettingsModify
SMS_WindowsDefenderAntimalwareSettingsRead
SMS_WindowsDefenderAntimalwareSettingsRun Report
SMS_WindowsDefenderAntimalwareSettingsSet Security Scope
SMS_WindowsDefenderApplicationGuardAuthor Policy
SMS_WindowsDefenderApplicationGuardRead
SMS_WindowsDefenderApplicationGuardRun Report
SMS_WindowsUpdateForBusinessConfigurationSettingsAuthor Policy
SMS_WindowsUpdateForBusinessConfigurationSettingsCreate
SMS_WindowsUpdateForBusinessConfigurationSettingsDelete
SMS_WindowsUpdateForBusinessConfigurationSettingsModify
SMS_WindowsUpdateForBusinessConfigurationSettingsRead
SMS_WindowsUpdateForBusinessConfigurationSettingsRun Report
SMS_WinRTSideLoadingKeyRead
SMS_WinRTSideLoadingKeyRun Report
SMS_WirelessProfileSettingsAuthor Policy
SMS_WirelessProfileSettingsRead
SMS_WirelessProfileSettingsRun Report
SMS_WSfBConfigurationDataRead



Related Information


Search UT EPM Documentation
Get Help

EPM is available to IT Support Organizations (ITSOs) with any endpoint management questions. If you have a question about a specific endpoint client, please reach out to your local endpoint client support organization.

SERVICE STATUS

Planned Maintenance

  • ConfigMgr: Every Tuesday, from 6 a.m. – 10 a.m.
  • Jamf: Every Tuesday, from 8 a.m. – 12 p.m.