For the complete documentation index, see llms.txt. This page is also available as Markdown.

Retrieving Device Recovery Keys from Intune and Kandji

Harmony can now retrieve device recovery keys directly from Microsoft Intune and Kandji. Your IT and security teams can access unlock PINs and recovery keys from within Harmony without switching between MDM consoles, reducing friction during device recovery and support workflows.

Supported MDM Platforms

Recovery key retrieval is supported for the following MDM platforms:

  • Microsoft Intune - recovery key retrieval is available as part of the existing Intune integration.

  • Kandji - recovery keys and unlock PINs are fetched via the Kandji Device Secrets API.

Prerequisites

Microsoft Intune

No additional configuration is required beyond your existing Intune integration. Recovery key retrieval is supported automatically once your Intune connection is active in Harmony.

Kandji

To enable recovery key retrieval for Kandji-managed devices, your Kandji API token must have the Device secrets permission enabled. Without this permission, Harmony cannot fetch recovery keys or unlock PINs from the Kandji Device Secrets API.

To verify or update your API token permissions:

  1. Log in to your Kandji admin console.

  2. Navigate to Settings and select Access or API Token management.

  3. Locate the API token used for your Harmony integration.

  4. Ensure the Device secrets permission is enabled on that token.

  5. Save your changes.

Once the permission is in place, Harmony will be able to retrieve recovery keys and unlock PINs for your Kandji-managed devices.

Retrieving Recovery Keys in Harmony

After the prerequisites are met, you can access device recovery keys directly from the Harmony interface:

  1. Open Harmony and navigate to the Devices section.

  2. Select the device for which you need the recovery key.

  3. Look for the Recovery Key or Unlock PIN option in the device details panel.

  4. Harmony fetches the key in real time from the connected MDM platform and displays it to authorized users.

Permissions and Access Control

Recovery key retrieval is a sensitive operation. Ensure that only authorized members of your IT and security teams have access to this functionality within Harmony. Review your Harmony role assignments to confirm that recovery key visibility is restricted to the appropriate users.

Troubleshooting

Issue
Likely Cause
Resolution

Recovery key not available for a Kandji device

Device secrets permission missing on the API token

Enable the Device secrets permission on your Kandji API token as described above

Recovery key not available for an Intune device

Intune integration not active or misconfigured

Verify your Intune connection is healthy in the Harmony integrations settings

Permission denied error when fetching key

Insufficient API token scope

Review and update the API token permissions in the respective MDM console

Last updated

Was this helpful?