SELECT-only account required. The SQL account used here must have read-only (SELECT) permission on the site database. This application never issues INSERT, UPDATE, DELETE, TRUNCATE, ALTER, CREATE or DROP statements against a Configuration Manager database, and never creates indexes on it.
Entra ID app registration
App-only (client credentials) access to Microsoft Graph, scoped to your tenant. The client secret is encrypted server-side and never returned to the browser.
Not configured
Required setup in the Microsoft Entra admin center
- Register a new application (single tenant) and copy the Directory and Application IDs.
- Under API permissions add the application permissions
DeviceManagementManagedDevices.Read.AllandDeviceManagementConfiguration.Read.All, then click Grant admin consent. - Do not grant any ReadWrite permission — the connection is rejected if one is present.
- Create a client secret and paste its value above. It is encrypted before storage.
Merged estate compliance
Configuration Manager and Intune folded into one device list. Co-managed devices take the worst state of both sources.
520 devices
0 co-managed
0 Intune only
520 ConfigMgr only
66.3% compliant
Intune update & policy states
Per-device states pulled from Microsoft Graph during the last sync.
No Intune states synced yet. Verify the app registration, then run a device sync.
Intune-managed devices
Most recent synced devices with their Configuration Manager correlation.
No Intune devices have been synced for this organization yet.