---
title: "ConfigMgr: Security Roles (Built-In)"
canonical: "https://kb.uconn.edu/space/IKB/10770814524/ConfigMgr%3A%20Security%20Roles%20(Built-In)"
format: markdown
---
<span style="color: #172b4d">M</span><span style="color: #333333">icrosoft System Center Configuration Manager </span><span style="color: #222222">(</span><span style="color: #333333">ConfigMgr) </span><span style="color: #222222">is a </span><span style="color: #333333">systems management </span><span style="color: #222222">software product developed by </span><span style="color: #333333">Microsoft </span><span style="color: #222222">for managing large groups of computers running the Microsoft Windows operating system.</span>

<span style="color: #172b4d">Faculty and staff can learn about built-in security roles for Microsoft System Center Configuration Management Console (ConfigMgr). </span>

## <span style="color: #172b4d">Security Role Descriptions</span>

<span style="color: #172b4d">Users can gain access to </span><span style="color: #333333">Microsoft System Center Configuration Manager </span><span style="color: #222222">(</span><span style="color: #333333">ConfigMgr) at UCONN via </span><span style="color: #333333">[Custom Security Roles](https://uconn.atlassian.net/wiki/spaces/IKB/pages/10770814532)</span><span style="color: #333333">. See the sections below for an overview of each role. </span>

### <span style="color: #172b4d">Application Administrator </span>

<span style="color: #172b4d">An Application Administrator grants permissions to perform both the Application Deployment Manager role and the Application Author role. Administrative users who are associated with this role can also do the following:</span>

- <span style="color: #172b4d">Manage queries</span>
- <span style="color: #172b4d">View site settings</span>
- <span style="color: #172b4d">Manage collections</span>
- <span style="color: #172b4d">Edit settings for user device affinity</span>
- <span style="color: #172b4d">Manage App-V virtual environments</span>

### Application Author

An Application Author grants permissions to create, modify, and retire applications. Administrative users who are associated with this role can also manage the following:

- Applications
- Packages
- App-V virtual environments

### Application Deployment Manager

An Application Deployment Manager grants permissions to deploy applications. Administrative users who are associated with this role can do the following:

- View a list of applications
- Manage deployments for the following:
  - Applications
  - Alerts
  - Templates and packages
  - Programs

Administrative users who are associated with this role can also view the following:

- Collections and their members
- Status messages
- Queries
- Conditional delivery rules
- App-V virtual environments

### Asset Manager

An Asset Manager grants permissions to manage the following:

- Asset Intelligence Synchronization Point
- Asset Intelligence reporting classes
- Software inventory
- Hardware inventory
- Metering rules

### Company Resource Access Manager

A Company Resource Access Manager grants permissions to create, manage, and deploy company resource access profiles like:

- Wi-Fi
- VPN
- Exchange ActiveSync email
- Certificate profiles to users and devices

### Compliance Settings Manager

A Compliance Settings Manager grants permissions to define and monitor Compliance Settings. Administrative users associated with this role can

- Create, modify, and delete configuration items and baselines
- Deploy configuration baselines to collections
- Initiate compliance evaluation
- Initiate remediation for non-compliant computers

### Endpoint Protection Manager

An Endpoint Protection Manager grants permissions to define and monitor security policies. Administrative users who are associated with this role can do the following:

- Create, modify and delete Endpoint Protection policies
- Deploy Endpoint Protection policies to collections
- Create and modify Alerts
- Monitor Endpoint Protection status

### Full Administrator

A Full Administrator grants all permissions in Configuration Manager. The administrative user who first creates a new Configuration Manager installation is associated with this security role, all scopes, and all collections.

### Infrastructure Administrator

<span style="color: #172b4d">An Infrastructure Administrator g</span>rants permissions to create, delete, and modify the Configuration Manager server infrastructure and to perform migration tasks.

### Operating System Deployment Manager

<span style="color: #172b4d">An Operating System Development Manager g</span>rants permissions to create operating system images and deploy them to computers. Administrative users who are associated with this role can manage the following:

- Operating system upgrade packages and images
- Task sequences
- Drivers
- Boot images
- State migration settings

### Operations Administrator

<span style="color: #172b4d">An Operations Administrator g</span>rants permissions for all actions in Configuration Manager except for the permissions that are required to manage security. These permissions include managing administrative users, security roles, and security scopes.

### <span style="color: #172b4d">Read-Only Analyst</span>

<span style="color: #172b4d">A Read Only-Analyst grants permissions to view all Configuration Manager objects.</span>

### <span style="color: #172b4d">Remote Tools Operator</span>

<span style="color: #172b4d">A Remote Tools Operator grants permissions to run and audit the remote administration tools that help users resolve computer issues. Administrative users that are associated with this role can run the following:</span>

- <span style="color: #172b4d">Remote Control, Remote Assistance, and Remote Desktop from the Configuration Manager console</span>
- <span style="color: #172b4d">Out of Band Management console </span>
- <span style="color: #172b4d">AMT power control options</span>

### Security Administrator

<span style="color: #172b4d">A Security Administrator g</span>rants permissions to add and remove administrative users and to associate administrative users with security roles, collections, and security scopes. Administrative users who are associated with this role can also create, modify, and delete security roles and their assigned security scopes and collections.

### Software Update Manager

<span style="color: #172b4d">A Software Update Manager g</span>rants permissions to define and deploy software updates. Administrative users who are associated with this role can manage the following:

- Software update groups
- Deployments
- Deployment templates

## Related Articles

> Macro (contentbylabel)

> Macro (details)