Microsoft Configuration Manager
Windows

How to Enumerate the Administrative Assignments for a User or Security Group

In brief

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

What Intune admins need to know

No administrator action is required; the updated metadata improves documentation categorization and discovery.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How to Enumerate the Administrative Assignments for a User or Security Group

The administrative assignments for a user or security group are defined by the roles and security scopes assigned to that user or security group. The Windows Management Instrumentation (WMI) SMS_Admin class contains all the administrators defined in Configuration Manager. The security roles for an admin are in the SMS_Admin.Roles property and the security scopes for an admin are in the SMS_Admin.Categories property. Both of these properties expose an array of strings which correspond to the identifier of the role or security scope. Both properties are also marked as lazy and are read-only.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…