Permissions
To connect your Atomicwork and Microsoft Intune accounts, you need:
Atomicwork admin access: You need org admin access in Atomicwork.
Permission | Usecase |
User.Read.All | Required to pull user device information |
DeviceManagementApps.ReadWrite.All | Required to read assignments and write assignments against users |
Group.ReadWrite.All | Required for a skill/AI workflow - to install apps on user devices |
DeviceManagementManagedDevices.PrivilegedOperations.All | Required for critical remote operations involving user devices like ‘Erase data’ and remote lock action |
DeviceManagementManagedDevices.Read.All | Required to read all the device information |
DeviceManagementManagedDevices.ReadWrite.All | Required for operations involving user devices like ‘Erase data’ and remote lock action |
Setup
As an Atomicwork admin, navigate to Settings > App Store > Microsoft Intune, and click on Connect.
Click on Enable to access a page that displays the permissions Atomicwork needs to successfully leverage the integration.
Click on Accept.
Atomicwork automatically ingests the full set of Microsoft Intune device attributes such as device hardware, OS and compliance state, enrollment status, last check-in, installed software, network configuration, and user assignment.
Admins do not need to manually select Intune fields or map remote Intune fields to Atomicwork attributes.
