Introduce Function-Based RBAC for Device Hub (Read-Only Device Health Role)
Enable organizations to grant access to Device Health and device monitoring capabilities without providing broader administrative permissions.
Problem Statement
Device Hub currently supports role-based access control based on geographic hierarchy:
- Global Administrator
- Country Administrator
- Location Administrator
While this allows organizations to delegate administration by region or location, it does not support access control based on function or responsibility.
Many organizations operate distributed support models where technical support teams need visibility into device health, diagnostics and operational alerts, but should not have access to broader administrative functions such as platform configuration or user management.
As a result, organizations must currently choose between:
- Granting broader privileges than required
- Restricting support teams from independently monitoring device health
Proposed Enhancement
Introduce function-based permissions within Device Hub.
Example:
Device Health Read-Only Role
Accessible:
- Device Health
- Device status
- Firmware visibility
- Diagnostic information
- Health alerts
Restricted:
- Device configuration
- Workspace configuration
- User administration
- Global settings
- Administrative functions
Business Value
- Supports least-privilege security principles
- Improves governance and compliance
- Enables scalable support models
- Reduces administrative dependency
- Improves operational efficiency
- Aligns with enterprise RBAC standards
Benefit Summary
Organizations can delegate monitoring responsibilities while maintaining appropriate governance and security controls.
-
Stephane Lamarchand
commented
Hello Damien! Indeed, strongly supported idea!
In enterprise environments, monitoring and administration are 2 different responsibilities. Local IT support teams need visibility into device health, alerts, firmware status and diagnostics, but do not require access to configuration settings or administrative functions.
A dedicated Device Health Read-Only role would:
- Enable proactive support and faster incident resolution
- Reduce administrative dependency
- Support least-privilege security principles
- Improve governance in multinational deployments
- Increase end-user satisfaction by reducing meeting room disruptionsThis functionality is already a standard RBAC capability in many enterprise management platforms and would greatly improve Device Hub adoption within large organizations.