Skip to main content
Status: Available (sub-feature of Azure AD integration)
Prerequisite: Azure AD integration must be connected first
License required: Microsoft Intune (included in M365 Business Premium, E3, E5)
Syncs: Managed devices, compliance policies, configuration profiles

Prerequisites

Intune data is synced as part of the Azure AD integration. The required permissions are already included in the Azure AD setup:
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementConfiguration.Read.All
No additional app registration steps are needed if you followed the Azure AD setup guide completely.

Verify Intune Permissions Are Granted

  1. Go to portal.azure.com → App registrations → SecurAtlas Integration
  2. Click API permissions
  3. Confirm these two permissions show Granted status:
    • DeviceManagementManagedDevices.Read.All
    • DeviceManagementConfiguration.Read.All
If not granted, click Grant admin consent.

What Gets Synced

EntityData
Managed devicesDevice name, OS, compliance state, last sync time
Compliance policiesPolicy name, assigned groups, settings
Configuration profilesProfile name, deployment status
App protection policiesMAM policies and protected apps

Troubleshooting

Confirm the tenant has active Intune licenses and at least one device enrolled. Check that DeviceManagementManagedDevices.Read.All is granted in the app registration.
The device may not have checked in recently. Intune compliance state requires the device to sync with Intune within the compliance policy check-in window (default 8 hours).