Skip to content

Microsoft Intune

Microsoft device management, reached through Microsoft Graph. Interchangeable with the other MDM connectors as far as the rest of the product is concerned.

Category MDM
Authentication OAuth client credentials
Reaches login.microsoftonline.com and graph.microsoft.com
Needs an agent No
Demo mode No

device.lookupBySerial, device.get and paginated device.list.

Which lights up device details on a repair, and the device page with live inventory.

For the relationship between registrations, Enterprise Applications and a future hosted consent flow, see Microsoft app registrations.

The current connector uses an application registered by your school and its server-side credentials. An Enterprise Application is the tenant’s local instance of an app registration; it is not an additional product to buy. A Plugboard sign-in/SSO app does not automatically authorize background imports. See Microsoft’s app model.

  1. Entra admin centre, Applications, App registrations, New registration.
  2. Name it Plugboard. Single tenant is correct. No redirect URI is needed, because this is a daemon flow rather than a user sign-in.
  3. Register, then note the Application (client) ID and the Directory (tenant) ID.
  4. API permissions, Add a permission, Microsoft Graph, Application permissions.
    • Add DeviceManagementManagedDevices.Read.All.
    • This also covers the connector’s optional detected-application inventory. Do not add write permissions merely to import devices or applications. Optional wipe and LAPS operations have separate configuration and permission requirements; enabling inventory does not enable them.
  5. Click Grant admin consent. This step is easy to miss, and without it the permission is requested but not effective.
  6. Certificates and secrets, New client secret.
    • Set an expiry you will track. Two years is common; twelve months is more honest about the review you will do.
    • Copy the Value, not the Secret ID. This is the single most common mistake. The value is only shown once.

Admin, Connectors, Microsoft Intune, Configure.

Field Value
tenantId Your Entra tenant id, or your domain such as yourschool.edu.au
collectApplications Optional, off by default. Collect detected applications during fleet sync, including paginated application/device relationships; cached for up to ten minutes
Field Value
clientId The Application (client) ID
clientSecret The secret value from step 6

Save and test. Success reports “Authenticated with Microsoft Graph”.

Client secrets expire, and when one does the connector stops working with a 401. Track the expiry explicitly rather than relying on an automatic reminder.

Put the expiry date in a shared calendar with a reminder a month out. Rotating is a two minute job; discovering the expiry at 8:40 on a Monday is not.

Field Notes
Serial number The lookup key
Model Falls back to the device name when the model is absent
Managed device id Used for subsequent calls
Assigned user The user principal name
Warranty expiry When Intune has it, which is not always

Intune does not carry AppleCare status. For Apple warranty detail, add Apple GSX alongside.

Common in schools with a mixed fleet: Macs in Jamf, Windows in Intune. Configure both. A device resolves through whichever knows its serial, and the repairs screen is unchanged either way.

Symptom Cause
401 on test Wrong secret, or you copied the Secret ID instead of the Value
403 or “insufficient privileges” Admin consent was not granted, or the wrong permission type was added. It must be an Application permission, not Delegated
Test passes, no devices found The serial is not in Intune, or the device is not enrolled. Lookups match on an uppercased serial
Worked, then stopped The client secret expired
AADSTS700016 The application id is wrong for that tenant

Jamf Pro, Kandji, Mosyle, Chrome Enterprise.