To enable Android Enterprise enrollment in Microsoft Intune, you need to have one of the following administrative roles in Azure Active Directory (Azure AD) that allow configuring device management settings:
Required Roles in Azure AD for Intune:
Global Administrator
Has full access to all aspects of Intune and Azure AD.
Recommended only if you need to manage all Azure/Intune configurations, as it’s the most privileged role.
Intune Administrator
Specific to managing Microsoft Intune.
This role allows you to manage devices, configure device enrollment, and assign policies, including enabling Android Enterprise.
Privileged Role Administrator
Can manage Azure AD role assignments, including assigning the Intune Administrator role to others.
Recommended Role for This Task:
Use the Intune Administrator role, as it’s tailored for device and enrollment configurations without granting unnecessary privileges.