Asset & Endpoint Management

Microsoft Intune

Microsoft Intune

Microsoft Intune: Permissions and setup

Permissions

To connect your Atomicwork and Microsoft Intune accounts, you need:

PermissionUsecase
User.Read.AllRequired to pull user device information
DeviceManagementApps.ReadWrite.AllRequired to read assignments and write assignments against users
Group.ReadWrite.AllRequired for a skill/AI workflow - to install apps on user devices
DeviceManagementManagedDevices.PrivilegedOperations.AllRequired for critical remote operations involving user devices like ‘Erase data’ and remote lock action
DeviceManagementManagedDevices.Read.AllRequired to read all the device information
DeviceManagementManagedDevices.ReadWrite.AllRequired for operations involving user devices like ‘Erase data’ and remote lock action

Setup

  • As an Atomicwork admin, navigate to Settings > App Store > Microsoft Intune, and click on Connect.
  • Click on Enable to access a page that displays the permissions Atomicwork needs to successfully leverage the integration.
  • Click on Accept.

Atomicwork automatically ingests the full set of Microsoft Intune device attributes such as device hardware, OS and compliance state, enrollment status, last check-in, installed software, network configuration, and user assignment.

Admins do not need to manually select Intune fields or map remote Intune fields to Atomicwork attributes.