Integrate with Intune MDM
If your district uses Intune, you can integrate it to sync your assets.
There are four tabs to set up the integration:
Users with the Manage Users and Permissions user permission can set up the integration.
|
Important: Because of the technical knowledge required, your district’s IT administrator (or someone with a similar role) should perform this procedure to integrate Intune. |
|
Notes:
|
Obtain credentials from the Microsoft Entra admin center
You will need the following credentials from the Microsoft Entra Admin Center to complete the integration:
- Tenant ID (Identity > Overview)
- Client ID
- Go to Identity > Applications > App Registrations.
- Enter a name, such as ITAM.
- Under Supported account type, select Accounts in this organizational directory only (MSFT only - Single tenant).
- The Client ID appears under App registrations > Overview.
- Client Secret
- Select Applications > App registrations > Destiny.
- Under Manage, select Certificates & secrets.
- Click + New client secret.
-
Enter a Description, and select an expiration date from the drop-down. Ensure you save the secret, as it is only visible until the page is closed.
-
Click Save.
Enter the Tenant ID, Client ID, and Client Secret in the Connection tab in IT Asset Manager. And then click Save.
Set up API permissions in the Microsoft Entra admin center
To use all of the features available in IT Asset Manager, you must have related privileges and access levels set up to read and write data, when needed.
- Sign in to the Microsoft Entra admin center.
- If you have access to multiple tenants, in the top-right corner, click the settings icon, and then select the desired directory name.
- Select Identity > Applications > App registrations > All applications, and select your client application.
- Select API permissions > + Add a permission.
- On the Request API permissions page, click Microsoft Graph.
- Add the following permissions:
- Delegated permissions
- User.read
- Application permissions
- AuditLog.Read.All
- BrowserSiteLists.Read.All
- Device.Read.All
- Device.ReadWrite.All
- DeviceManagementConfiguration.Read.All
- DeviceManagementConfiguration.ReadWrite.All
- DeviceManagementManagedDevices.PrivilegedOperations.All
- DeviceManagementManagedDevices.Read.All
- DeviceManagementManagedDevices.ReadWrite.All
- DeviceManagementRBAC.Read.All
- DeviceManagementRBAC.ReadWrite.All
- DeviceManagementServiceConfig.Read.All
- Directory.Read.All
- Directory.ReadWrite.All
- Directory.Write.Restricted
- Group.Create
- Group.Read.All
- Group.ReadWrite.All
- GroupMember.Read.All
- GroupMember.ReadWrite.All
- Place.Read.All
- Delegated permissions
- In IT Asset Manager, on the Connection tab, you can test the connection with your credentials
Set up the Intune integration in IT Asset Manager
In IT Asset Manager, select Settings > Integrations > Intune Integration.
The Connection tab requires you to obtain information from Intune to set up the link. Contact Intune support, or access their help documentation, if you need more information.
To set up a link to Intune:
- Enter your Intune Tenant ID, Client ID, and Client Secret.
- Click Save.
Note: If you have not set up permissions in the Microsoft Entra admin center, do so now.
- To test the connection with your credentials, click Test.
Note: Once the integration is active, a green banner message appears at the top-left.
- Click Next to go to the Field Mapping tab.
The Serial # and Model fields are automatically mapped.
|
Note: If the Serial # field matches in both systems, the existing asset is updated. Otherwise, a new asset record is created. |
Select the Intune field you want to map to the Asset Name and Barcode fields. The following fields are options:
- Serial #
- Mobile device name
Click Next to go to the Sync Rules tab.
Use this tab to customize the sync rules of how to update Intune when something happens in Work Orders.
To set up the sync rules:
- Select/deselect the If Follett changes the asset Status To Lost > Set the device's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
- Don't Change
- Cleaned
- Deleted
- Retired
- Wiped
- From the and Move the device to Device Category drop-down, select one of the following:
- Don't Move
- Lost
- Stolen Devices
- Select/deselect the If Follett changes the asset Status to Stolen > Set the device's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
- Don't Change
- Cleaned
- Deleted
- Retired
- Wiped
- From the and Move the device to Device Category drop-down, select one of the following:
- Don't Move
- Lost
- Stolen Devices
- Select/deselect theIf Follett changes the asset Building/Space > Move the item in Intune to the Mapped Device Category checkbox to enable/disable from syncing.
- Select/deselect the If Follett deletes an asset > Set the item's Status in Intune to checkbox to enable/disable from syncing. From the drop-down, select one of the following:
- Don't Change
- Cleaned
- Deleted
- Retired
- Wiped
- From the and Move the device to Device Category drop-down, select one of the following:
- Don't Move
- Lost
- Stolen Devices
- Click Save Rules.
- Click Next to go to the Sync Data tab.
Use the Sync Data tab to add device categories. The sync brings in devices tagged to a category added on this tab.
To add a category, and sync your devices:
- Click + Add Device Category. A pop-up appears.

- Select the Intune Device Category Name from the drop-down.
- Select a Building and Space.
Note: The Building and Space can be changed after they are synced.
- To ensure this category continues to sync, leave the Active checkbox selected.
- Click Save.
- Click OK.
- To initiate a sync for the group, click
. - When the sync is complete, a pop-up shows the total number of devices, total updated, total added, and total not synced. Click OK.
Assets that are synced from Intune will show an Intune icon next to their name. You can click the icon to open a window with all available Intune device fields.