Microsoft Intune
Microsoft Intune is a cloud-based endpoint management solution that helps organizations manage mobile devices, desktops, and applications. Connecting Intune to Harmony enables automated device provisioning, intelligent compliance monitoring, and AI-powered troubleshooting for your entire endpoint fleet.
What the Microsoft Intune integration enables
Device Inventory
Sync all managed devices with real-time status and compliance data
Automated Provisioning
Trigger device enrollment and configuration through Harmony workflows
Compliance Monitoring
Track compliance policies and automate remediation actions
Remote Actions
Execute remote wipe, lock, restart, and other management tasks
AutoPilot Visibility
Surface pre-enrollment AutoPilot devices as In Stock assets
App Discovery
Automatically populate installed application data from Intune
Recovery Keys
Retrieve BitLocker and FileVault recovery keys for managed devices
Prerequisites
Before configuring the Microsoft Intune integration, ensure you have:
Microsoft 365 Administrator Access: Global Administrator or Intune Administrator role
Harmony Account: Active Harmony workspace with integration permissions
Connect Microsoft Intune to Harmony
Step 1: Navigate to Integrations
Log in to your Harmony dashboard
Go to Settings > Integrations
Find Microsoft Intune under MDM and click Connect

Step 2: Configure Instance
Enter an Instance name for your Microsoft Intune connection (e.g., "Microsoft Intune Instance")
Click Connect to start the authentication process

Step 3: Authorize in Microsoft
You'll be redirected to Microsoft's permissions page
Sign in with your Microsoft 365 administrator account
Review the requested permissions for managing Intune devices and policies
Click Accept to authorize Harmony to access your Intune instance
Harmony uses a secure OAuth authorization flow for this step, consistent with Microsoft's recommended security standards. You do not need to manage credentials or client secrets manually.

What Harmony Syncs
From Intune to Harmony
Device Inventory: All enrolled devices with hardware details, discovered using Azure AD device targeting for accurate identification
Compliance Status: Real-time compliance policy status
Device Health: Battery health, storage, encryption status
Installed Apps: List of installed applications on each device, automatically filtered with an ignore list to remove system-level noise
User Assignments: Primary user for each device
Device Groups: Group memberships and assignments
Last Sync: Last check-in timestamp
Network Interfaces: IP addresses for Wi-Fi, Ethernet, VPN, Docker, WSL, and other interfaces
Device Ownership: Company-owned or Personal, sourced from Intune's
managedDeviceOwnerTypefieldAutoPilot Devices: Pre-enrollment devices registered in AutoPilot, surfaced as In Stock assets
Recovery Keys: BitLocker recovery keys for Windows devices and FileVault recovery keys for encrypted macOS devices
AutoPilot Device Visibility
Harmony automatically discovers devices registered in Microsoft Intune AutoPilot before they are enrolled and actively managed. This gives you full visibility into your pre-deployment device fleet without any manual action.
AutoPilot devices appear as In Stock assets as soon as they are registered in Intune, even before enrollment begins
Automatic status transition: once a device enrolls in Intune, it automatically moves from In Stock to Active
Devices are marked as Company Owned to reflect their organizational ownership
Recovery Key Collection
Harmony collects and securely stores recovery keys for encrypted devices managed through Intune.
BitLocker (Windows)
Harmony retrieves all BitLocker key metadata in a single paginated bulk request, reducing Microsoft Graph API calls by approximately 50% compared to per-device lookups. When multiple keys exist for a device, Harmony intelligently prefers the OS volume key and the most recently created key. If the BitLockerKey.Read.All permission has not been granted, BitLocker key collection is skipped gracefully without affecting other sync operations.
FileVault (macOS)
FileVault recovery keys are automatically collected from Intune-managed macOS devices where disk encryption is confirmed active. Keys are encrypted immediately upon collection and stored securely in the device's asset record. FileVault key collection is independent of BitLocker key collection and does not affect Windows device sync.
Application Discovery
Harmony automatically pulls software inventory data collected by Intune and populates it into your Applications catalogue. An ignore list is applied automatically to filter out noise and system-level entries that are not meaningful for software discovery. No additional configuration is required.
Network Interface Data
Harmony accurately populates IP address data for all network interfaces on Intune-managed devices:
Wi-Fi interfaces show the correct IPv4 address, sourced from the device's primary IP field
Ethernet interfaces display their wired IPv4 address
Additional interfaces - including VPN, Docker, and WSL networks - are discovered and listed as separate entries
Device Ownership
Harmony reads Intune's managedDeviceOwnerType field and reflects it in your asset records, mapping both Company and Personal ownership types. Existing synced data is updated automatically without requiring a new data collection. The Personal ownership type is also available in the ownership dropdown across your asset inventory.
Troubleshooting
Best Practices
Data & Privacy
Last updated
Was this helpful?
