Integrate with Intune MDM

If your district uses Intune, you can integrate it to sync your assets.

There are four tabs to set up the integration:

Users with the Manage Users and Permissions user permission can set up the integration.

Important: Because of the technical knowledge required, your district’s IT administrator (or someone with a similar role) should perform this procedure to integrate Intune.

Notes:

  • New devices and updates to existing assets from the MDM sync nightly, while sync rule actions are processed every 30 minutes.
  • Once an Intune device is synced, mapped fields on the asset record CANNOT be edited. Otherwise, most fields on the asset record are still editable.
  • The integration does the following in regards to asset creation:
    • Uses the serial number of the Intune device to uniquely identify it.
    • If it finds a matching serial number, it updates the existing IT Asset Manager asset record with the Intune information; if not, it creates a new asset record.

Obtain credentials from the Microsoft Entra admin center

You will need the following credentials from the Microsoft Entra Admin Center to complete the integration:

  1. Tenant ID (Identity > Overview)
  2. Client ID
    1. Go to Identity > Applications > App Registrations.
    2. Enter a name, such as ITAM.
    3. Under Supported account type, select Accounts in this organizational directory only (MSFT only - Single tenant).
    4. The Client ID appears under App registrations > Overview.
  3. Client Secret
    1. Select Applications > App registrations > Destiny.
    2. Under Manage, select Certificates & secrets.
    3. Click + New client secret.
    4. Enter a Description, and select an expiration date from the drop-down. Ensure you save the secret, as it is only visible until the page is closed.

    5. Click Save.

Enter the Tenant ID, Client ID, and Client Secret in the Connection tab in IT Asset Manager. And then click Save.

Set up API permissions in the Microsoft Entra admin center

To use all of the features available in IT Asset Manager, you must have related privileges and access levels set up to read and write data, when needed.

  1. Sign in to the Microsoft Entra admin center.
  2. If you have access to multiple tenants, in the top-right corner, click the settings icon, and then select the desired directory name.
  3. Select Identity > Applications > App registrations > All applications, and select your client application.
  4. Select API permissions > + Add a permission.
  5. On the Request API permissions page, click Microsoft Graph.
  6. Add the following permissions:
    • Delegated permissions
      • User.read
    • Application permissions
      • AuditLog.Read.All
      • BrowserSiteLists.Read.All
      • Device.Read.All
      • Device.ReadWrite.All
      • DeviceManagementConfiguration.Read.All
      • DeviceManagementConfiguration.ReadWrite.All
      • DeviceManagementManagedDevices.PrivilegedOperations.All
      • DeviceManagementManagedDevices.Read.All
      • DeviceManagementManagedDevices.ReadWrite.All
      • DeviceManagementRBAC.Read.All
      • DeviceManagementRBAC.ReadWrite.All
      • DeviceManagementServiceConfig.Read.All
      • Directory.Read.All
      • Directory.ReadWrite.All
      • Directory.Write.Restricted
      • Group.Create
      • Group.Read.All
      • Group.ReadWrite.All
      • GroupMember.Read.All
      • GroupMember.ReadWrite.All
      • Place.Read.All
  7. In IT Asset Manager, on the Connection tab, you can test the connection with your credentials

Set up the Intune integration in IT Asset Manager

In IT Asset Manager, select Settings > Integrations > Intune Integration.

Step 1: Connection tab

Intune integration Connection tab.

The Connection tab requires you to obtain information from Intune to set up the link. Contact Intune support, or access their help documentation, if you need more information.

To set up a link to Intune:

  1. Enter your Intune Tenant ID, Client ID, and Client Secret.
  2. Click Save.

    Note: If you have not set up permissions in the Microsoft Entra admin center, do so now.

  3. To test the connection with your credentials, click Test.

    Note: Once the integration is active, a green banner message appears at the top-left.

  4. Click Next to go to the Field Mapping tab.

Step 2: Field Mapping tab

Intune integration, Field Mapping tab.

The Serial # and Model fields are automatically mapped.

Note: If the Serial # field matches in both systems, the existing asset is updated. Otherwise, a new asset record is created.

Select the Intune field you want to map to the Asset Name and Barcode fields. The following fields are options:

  • Serial #
  • Mobile device name

Click Next to go to the Sync Rules tab.

Step 3: Sync Rules tab

Intune integration, Sync Rules tab.

Use this tab to customize the sync rules of how to update Intune when something happens in Work Orders.

To set up the sync rules:

  1. Select/deselect the If Follett changes the asset Status To Lost > Set the device's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
    • Don't Change
    • Cleaned
    • Deleted
    • Retired
    • Wiped
  2. From the and Move the device to Device Category drop-down, select one of the following:
    • Don't Move
    • Lost
    • Stolen Devices
  3. Select/deselect the If Follett changes the asset Status to Stolen > Set the device's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
    • Don't Change
    • Cleaned
    • Deleted
    • Retired
    • Wiped
  4. From the and Move the device to Device Category drop-down, select one of the following:
    • Don't Move
    • Lost
    • Stolen Devices
  5. Select/deselect theIf Follett changes the asset Building/Space > Move the item in Intune to the Mapped Device Category checkbox to enable/disable from syncing.
  6. Select/deselect the If Follett deletes an asset > Set the item's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
    • Don't Change
    • Cleaned
    • Deleted
    • Retired
    • Wiped
  7. From the and Move the device to Device Category drop-down, select one of the following:
    • Don't Move
    • Lost
    • Stolen Devices
  8. Click Save Rules.
  9. Click Next to go to the Sync Data tab.

Step 4: Sync Data tab

Intune integration, Sync Data tab.

Use the Sync Data tab to add device categories. The sync brings in devices tagged to a category added on this tab.

To add a category, and sync your devices:

  1. Click + Add Device Category. A pop-up appears.
    Manage Intune Device Category page.
  2. Select the Intune Device Category Name from the drop-down.
  3. Select a Building and Space.

    Note: The Building and Space can be changed after they are synced.

  4. To ensure this category continues to sync, leave the Active checkbox selected.
  5. Click Save.
  6. Click OK.
  7. To initiate a sync for the group, click Sync data icon..
  8. When the sync is complete, a pop-up shows the total number of devices, total updated, total added, and total not synced. Click OK.

Assets that are synced from Intune will show an Intune icon next to their name. You can click the icon to open a window with all available Intune device fields.