I need a Helpdesk role that allows users to:
Select applications from the Patch My PC catalog
Upload custom applications
Access the Deployment blade to deploy catalog and custom applications
No access to the Settings blade
Currently, it seems that achieving this level of granularity is not possible without granting Full Admin rights. However, this does expose all things in the Settings blade.
The goal is to implement proper Role-Based Access Control (RBAC) while ensuring Helpdesk users can manage apps efficiently without over-permission.