We are reviewing the permissions given to people that need to enroll their device (macOS only) by either DEP/ADE or user initiated permissions.
First question, do DEP/ADE and user-initiated require the same permissions?
Second question, what are the minimum required permissions?
The strange thing is that the permissions for :
Allow User to Enroll |
Assign Users to Computers |
Assign Users to Mobile Devices |
Enroll Computers and Mobile Devices |
are not assigned, but no one reports any issue.
When looking to the default role that allows people to enroll their device it seems to assign way to much.
Anyone that knows the ins and outs?