Changes for page acmp Intune Connector
Last modified by Sabrina V. on 2026/10/08 08:36
From version 2.1
edited by Sabrina V.
on 2024/10/23 06:03
on 2024/10/23 06:03
Change comment:
There is no comment for this version
To version 8.1
edited by Sabrina V.
on 2026/10/08 08:36
on 2026/10/08 08:36
Change comment:
There is no comment for this version
Summary
-
Page properties (2 modified, 0 added, 0 removed)
Details
- Page properties
-
- Title
-
... ... @@ -1,1 +1,1 @@ 1 - ACMPIntune Connector1 +acmp Intune Connector - Content
-
... ... @@ -4,219 +4,64 @@ 4 4 5 5 {{aagon.floatingbox/}} 6 6 7 -Microsoft Intune is a cloud-based solution that helps you manage your mobile devices. It allows you to remotely manage devices, secure access or even lock them down. With the ACMP Intune Connector, you can inventory the devices from Intune in ACMP and send the most important actions to the devices from ACMP. 7 +{{aagon.versionierungsbox}} 8 +Please note that the acmp Intune Connector has been replaced by [[Intune Management>>doc:ACMP.610.ACMP-Solutions.Intune Management.WebHome]] in version 6.8 of acmp. 9 +{{/aagon.versionierungsbox}} 8 8 9 - =**Requirementsfor usingtheACMPIntune Connector**=11 +Microsoft Intune is a cloud-based solution that helps you manage your mobile devices. It allows you to remotely manage devices, secure access or even lock them down. With the acmp Intune Connector, you can inventory the devices from Intune in acmp and send the most important actions to the devices from acmp. 10 10 11 - To usetheACMPIntune Connector,the following requirements must be met:13 += **Requirements for using the acmp Intune Connector** = 12 12 13 -* You need a user account with the appropriate permissions for Microsoft Azure Active Directory 14 -* There must be a connection between AESB and ACMP. AESB must be available for this and the necessary details of the [[SICS connection>>doc:||anchor="H1.ACMPconsole:CheckSICSconnectioninACMP"]] must be stored in ACMP 15 -* AESB must be at least version 1.8 16 -* You need a working internet connection, as Intune is a cloud solution and requires a network connection to work. 17 -* A running instance of Intune 15 +To use the acmp Intune Connector, the following requirements must be met: 18 18 19 - =PreparationsinAzureActiveDirectory=17 +* You need a user account with the appropriate permissions for Microsoft Entra ID 20 20 21 -To enable the ACMP Intune Connector to access the Intune API, you must first register an enterprise application in Azure Active Directory and grant the required permissions within those applications. 19 +{{box}} 20 +Refer to the [[//Registering an enterprise application in Microsoft Entra ID//>>doc:ACMP.610.Unternehmensanwendung registrieren in der Microsoft Entra ID.WebHome]] section for information on how to register an app and distribute the necessary permissions. 21 +{{/box}} 22 22 23 -== Register the Enterprise Application == 23 +* There must be a connection between aesb and acmp. aesb must be available for this and the necessary details of the [[SICS connection>>doc:||anchor="H1.ACMPconsole:CheckSICSconnectioninacmp"]] must be stored in acmp 24 +* aesb must be at least version 1.8 25 +* You need a working internet connection, as Intune is a cloud solution and requires a network connection to work. 26 +* A running instance of Intune 24 24 25 - First,sign in to the [[AzureAD (Active Directory)>>https://aad.portal.azure.com/]]and navigate toAzureActive Directoryinthe Overview. Click the //Manage//>//Application////Registrations// taband createa new application registration.28 += Prepare for Microsoft Entra ID and distribute permissions = 26 26 27 -{{figure}} 28 -[[image:65_Intune_App-Registrierung in der Azure AD.png||data-xwiki-image-style-alignment="center"]] 30 +In order for the acmp Intune Connector to access the Intune API, you must first register a company application in the Microsoft Entra Admin Centre and grant the necessary permissions within these applications (see [[//Registering a company application in Microsoft Entra ID//>>doc:ACMP.610.Unternehmensanwendung registrieren in der Microsoft Entra ID.WebHome]]). 29 29 30 -{{figureCaption}} 31 -App registrations in the Azure AD 32 -{{/figureCaption}} 33 -{{/figure}} 32 += Configuration in aesb and acmp = 34 34 35 - Enterall thenecessaryinformation:Enteranamefortheapplicationand selecttheaccountstosupport.Finishtheprocessbyclicking //Register//.34 +Before you can use Intune in acmp, you need to do some preliminary work in the acmp and aesb consoles. 36 36 37 -{{figure}} 38 -[[image:65_Intune_Anwendung registrieren.png||data-xwiki-image-style-alignment="center"]] 36 +== 1. **acmp console: Check SICS connection in acmp** == 39 39 40 -{{figureCaption}} 41 -Register application 42 -{{/figureCaption}} 43 -{{/figure}} 38 +It is necessary that you have a working SICS connection in acmp. To do this, go to //System// > //Settings// > //acmp Server// > //SICS Connection//. First tick the box to enable the connection. Then enter the host and port, as well as the user name and password for the operator. You specified the corresponding operator during the installation of the aesb, which you must also specify here. Specify whether to attempt an unencrypted connection if SSL/TLS fails. Then test the connection. 44 44 45 - If younowopenthecreated application,youwill seeasummaryofthe information added.Thisincludesthedisplay name,the variousIDs(application,objectanddirectoryID)and detailsofthe account typessupported.40 +Also tick the Public API access rights box to grant access. You can now save your settings. acmp and SICS are now connected to each other. 46 46 47 47 {{figure}} 48 -[[image:65_Intune_Zusammenfassung der Anwendungsinformationen.png||alt="65_Intune_Anwendung registrieren.png" data-xwiki-image-style-alignment="center"]] 49 - 50 -{{figureCaption}} 51 -Summary of the application information 52 -{{/figureCaption}} 53 -{{/figure}} 54 - 55 -== Distribute permissions == 56 - 57 -The next step is to assign the necessary permissions to the business application to access the Graph API. To do this, go to the Permissions section within the registered application (//Manage// > //API// //Permissions//). 58 - 59 -{{figure}} 60 -[[image:65_Intune_API Berechtigungen.png||data-xwiki-image-style-alignment="center"]] 61 - 62 -{{figureCaption}} 63 -API permissions 64 -{{/figureCaption}} 65 -{{/figure}} 66 - 67 -There, click //Add Permission//. This will bring up a page where you can request the API permissions. In this step you need to select the //Microsoft Graph//. 68 - 69 -{{figure}} 70 -[[image:65_Intune_Microsoft Graph anfordern.png||data-xwiki-image-style-alignment="center"]] 71 - 72 -{{figureCaption}} 73 -API permissions: Request Microsoft Graph 74 -{{/figureCaption}} 75 -{{/figure}} 76 - 77 -A distinction is made between "Delegated Permissions" and "Application Permissions". Enter the following values individually under 'Delegated permissions' and repeat the process by entering each of the following list entries: 78 - 79 -* DeviceManagementManagedDevices.Read.All 80 -* DeviceManagementManagedDevices.ReadWrite.All 81 -* User.Read 82 - 83 -{{figure}} 84 -[[image:65_Intune_Delegierte Berechtigungen verteilen.png||data-xwiki-image-style-alignment="center"]] 85 - 86 -{{figureCaption}} 87 -Distribute delegated permissions 88 -{{/figureCaption}} 89 -{{/figure}} 90 - 91 -Tick the appropriate items, scroll back to the top, click the //Application Permissions// field and add the following permissions: 92 - 93 -* DeviceManagementApps.Read.All 94 -* DeviceManagementConfiguration.Read.All 95 -* DeviceManagementManagedDevices.PrivilegedOperations.All 96 -* DeviceManagementManagedDevices.Read.All 97 -* DeviceManagementManagedDevices.ReadWrite.All 98 -* DeviceManagementServiceConfig.Read.All 99 -* User.Read.All 100 - 101 -When you have selected all the permissions, click //Add Permissions//. You will see the entries in the overview. 102 - 103 -{{figure}} 104 -[[image:65_Intune_Verteilte Berechtigungen (ohne Einwilligung).png||data-xwiki-image-style-alignment="center"]] 105 - 106 -{{figureCaption}} 107 -Deployed permissions (without consent) 108 -{{/figureCaption}} 109 -{{/figure}} 110 - 111 -If you have not already done so, you may need to give your consent to the permissions. To do this, click on the //Grant administrator// //consent for// //"%Your Company%//" field. This will change the status and the user permission will be granted. 112 - 113 -{{figure}} 114 -[[image:65_Intune_Bewilligte Berechtigungen.png||data-xwiki-image-style-alignment="center"]] 115 - 116 -{{figureCaption}} 117 -Authorised permissions 118 -{{/figureCaption}} 119 -{{/figure}} 120 - 121 -== Upload client secret key or certificates == 122 - 123 -Later, during the initial setup of the ACMP Intune Connector, you have to specify an authentication type in the AESB console. You can choose from two methods supported by the Microsoft Client Credentials Provider: //Certificate// or //Client Secret Key//. 124 - 125 -{{aagon.infobox}} 126 -The procedure differs depending on the authentication type selected. Read below to find out what you need to consider for each method. 127 -{{/aagon.infobox}} 128 - 129 -=== Upload certificate === 130 - 131 -{{aagon.infobox}} 132 -Due to the higher level of security, Microsoft recommends that you use a certificate as your credential. 133 -{{/aagon.infobox}} 134 - 135 -Certificates can be used as an authentication method to log in to Azure Active Directory in the AESB console. A certificate always consists of a public and private part, where the public key is loaded directly into Azure AD. The private part is used in the AESB console. This certificate pair needs to be generated beforehand. Read how to generate a certificate via [[Microsoft>>url:https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate?tabs=apex%2Cportal]] or[[ Open SSL>>url:https://stackoverflow.com/questions/6307886/how-to-create-pfx-file-from-certificate-and-private-key]]. 136 - 137 -Navigate to //Certificates & Secrets// in the previously registered application. In the details, click on the //Certificates// tab and upload the previously created certificate. 138 - 139 -{{figure}} 140 -[[image:65_Intune_Zertifikat hochladen.png||data-xwiki-image-style-alignment="center"]] 141 - 142 -{{figureCaption}} 143 -Upload certificate 144 -{{/figureCaption}} 145 -{{/figure}} 146 - 147 -A field will open on the right hand side where you can upload the certificate. Browse to the appropriate directory, upload the file and enter an optional description for the certificate. Then click Add and the certificate will be saved for the application. 148 - 149 -{{aagon.infobox}} 150 -Please note that only .cer, .pem and .crt file types are supported when uploading a certificate. 151 -{{/aagon.infobox}} 152 - 153 -{{figure}} 154 -[[image:65_Intune_Hochgeladenes Zertifikat in der Azure Active Directory.png||data-xwiki-image-style-alignment="center"]] 155 - 156 -{{figureCaption}} 157 -Uploaded certificate in the Azure Active Directory 158 -{{/figureCaption}} 159 -{{/figure}} 160 - 161 -=== Adding a secret client key === 162 - 163 -The secret client key is a string of characters used by the enterprise application as an authentication key or proof of identity when requesting the token. To do this, go to the Permissions area within the registered application (//Security// > //Permissions//) and click the Application Registration link. Navigate to //Certificates// & //Secrets//. In the details, click the //Secret Client Keys// tab and create a new key. 164 - 165 -{{figure}} 166 -[[image:65_Intune_Neuen Clientschlüssel hinterlegen.png||data-xwiki-image-style-alignment="center"]] 167 - 168 -{{figureCaption}} 169 -Store new client key 170 -{{/figureCaption}} 171 -{{/figure}} 172 - 173 -When creating a new secret client key, you can configure the validity period. Note that once the validity period has expired, a new key must be created and stored in the AESB. 174 - 175 -{{figure}} 176 -[[image:65_Intune_Geheimen Clientschlüssel hinterlegen.png||data-xwiki-image-style-alignment="center"]] 177 - 178 -{{figureCaption}} 179 -Adding a secret client key 180 -{{/figureCaption}} 181 -{{/figure}} 182 - 183 -{{aagon.infobox}} 184 -You will need the secret client key you created when you set up the AESB. Keep this in mind for future reference. 185 -{{/aagon.infobox}} 186 - 187 -= Configuration in AESB and ACMP = 188 - 189 -Before you can use Intune in ACMP, you need to do some preliminary work in the ACMP and AESB consoles. 190 - 191 -== 1. **ACMP console: Check SICS connection in ACMP** == 192 - 193 -It is necessary that you have a working SICS connection in ACMP. To do this, go to //System// > //Settings// > //ACMP Server// > //SICS Connection//. First tick the box to enable the connection. Then enter the host and port, as well as the user name and password for the operator. You specified the corresponding operator during the installation of the AESB, which you must also specify here. Specify whether to attempt an unencrypted connection if SSL/TLS fails. Then test the connection. 194 - 195 -Also tick the Public API access rights box to grant access. You can now save your settings. ACMP and SICS are now connected to each other. 196 - 197 -{{figure}} 198 198 [[image:65_Intune_SICS-Verbindung_575.png||alt="65_ACMP_Einstellungen_SICS Verbindung.png" data-xwiki-image-style-alignment="center"]] 199 199 200 200 {{figureCaption}} 201 -Set up SICS connection in ACMP46 +Set up SICS connection in acmp 202 202 {{/figureCaption}} 203 203 {{/figure}} 204 204 205 -== 2. AESBconsole: **Install and configure the Intune Connector** ==50 +== 2. aesb console: **Install and configure the Intune Connector** == 206 206 207 -Now go to the AESBconsole. From the Dashboard, navigate to the //Products// menu item. In the overview you will find a list of all packages available for installation or updates. Select //ACMPIntune Adapter// and click //Install// either in the quick selection bar or directly in the fields. A new window will open and the installation will begin.52 +Now go to the aesb console. From the Dashboard, navigate to the //Products// menu item. In the overview you will find a list of all packages available for installation or updates. Select //acmp Intune Adapter// and click //Install// either in the quick selection bar or directly in the fields. A new window will open and the installation will begin. 208 208 209 209 {{figure}} 210 210 [[image:65_AESB_Übersicht des ACMP Intune Adapters in der AESB Console.png||data-xwiki-image-style-alignment="center"]] 211 211 212 212 {{figureCaption}} 213 -Overview of the ACMPIntune Adapter in theAESBConsole58 +Overview of the acmp Intune Adapter in the aesb Console 214 214 {{/figureCaption}} 215 215 {{/figure}} 216 216 217 -The first step tells you what you need to have already done to successfully install the Intune Adapter: You need a configured and working Microsoft Intune instance and a working ACMPSICS connection. In the second step of the installation wizard, you have the option to assign a template name at the top of the pages.62 +The first step tells you what you need to have already done to successfully install the Intune Adapter: You need a configured and working Microsoft Intune instance and a working acmp SICS connection. In the second step of the installation wizard, you have the option to assign a template name at the top of the pages. 218 218 219 -Under //Intune Connector Configuration//, you can set basic settings for the Intune Connector. Under ACMPServer ID, you need to specify the server to which the changes will be sent. If you enter an asterisk, the changes will be sent to allACMPservers that have a SICS connection and whose connection information is identical to the information you entered in step //[[1.ACMPconsole: Check SICS connection inACMP>>doc:||anchor="H1.ACMPconsole:CheckSICSconnectioninACMP"]]//. You can also specify the name of the workflow instance under which the settings are to be sent. You can do this under //Ondemand definition name//.64 +Under //Intune Connector Configuration//, you can set basic settings for the Intune Connector. Under acmp Server ID, you need to specify the server to which the changes will be sent. If you enter an asterisk, the changes will be sent to all acmp servers that have a SICS connection and whose connection information is identical to the information you entered in step //[[1. acmp console: Check SICS connection in acmp>>doc:||anchor="H1.ACMPconsole:CheckSICSconnectioninacmp"]]//. You can also specify the name of the workflow instance under which the settings are to be sent. You can do this under //Ondemand definition name//. 220 220 221 221 In the //Intune Configuration// menu item, you can now use one of the two login methods: the secret client key or a certificate. 222 222 ... ... @@ -248,10 +248,10 @@ 248 248 249 249 === Option 2: **Secret client key authentication method:** === 250 250 251 -Select //secret client key// as the authentication type. Under //secret client key//, enter the value that you generated as the secret key on the [[Azure Active Directory pages>>doc:||anchor="HUploadclientsecretkeyorcertificates"]].96 +Select //secret client key// as the authentication type. Under //secret client key//, enter the value that you generated as the secret key on the [[Azure Active Directory pages>>doc:||anchor="HUploadclientsecretkeyorcertificates"]]. 252 252 253 253 {{aagon.infobox}} 254 -Please note that the value is displayed in abbreviated form. This means that it will have a different character length when entered in the AESBconsole.99 +Please note that the value is displayed in abbreviated form. This means that it will have a different character length when entered in the aesb console. 255 255 {{/aagon.infobox}} 256 256 257 257 {{figure}} ... ... @@ -282,7 +282,7 @@ 282 282 283 283 Click //Verify Connection//. If the connection is successful, you will be taken to the //scanner configuration//, where you can optionally set time intervals for the scanner. If you do not want to make any changes, click //Next//. 284 284 285 -The Intune adapter installation will begin in the background. When the installation is complete and all items have been successfully installed, you can click //Finish//. You will be returned to the AESBConsole Overview page. There are several places in theAESBConsole where you can check that the installation was successful and that all the required applications are available:130 +The Intune adapter installation will begin in the background. When the installation is complete and all items have been successfully installed, you can click //Finish//. You will be returned to the aesb Console Overview page. There are several places in the aesb Console where you can check that the installation was successful and that all the required applications are available: 286 286 287 287 |**Navigation point**|**Description** 288 288 |Microservices|Below the Supervisors & microservice instances, you will see the entries //IntuneConnector_1 //and //IntuneWorkflowEngine_1//. ... ... @@ -289,12 +289,12 @@ 289 289 |Workflows|Within the Workflow engines & instances section, the entries //IntuneWorkflowEngine_1 //and //IntuneMobileDevices_1 //must be listed. 290 290 291 291 {{aagon.infobox}} 292 -You can also install the Intune Connector more than once. This allows you to use both the secret client key and the certificate as the authentication type. A dual installation is useful, for example, if you are using multiple ACMPservers and want the data to flow to them. Multiple installations will increment the microservices and workflow entries. In this case, you would have, for example, //IntuneWorkflowEngine_1//,// IntuneWorkflowEngine_2, and IntuneMobileDevices_1 and IntuneMobileDevices_2//.137 +You can also install the Intune Connector more than once. This allows you to use both the secret client key and the certificate as the authentication type. A dual installation is useful, for example, if you are using multiple acmp servers and want the data to flow to them. Multiple installations will increment the microservices and workflow entries. In this case, you would have, for example, //IntuneWorkflowEngine_1//,// IntuneWorkflowEngine_2, and IntuneMobileDevices_1 and IntuneMobileDevices_2//. 293 293 {{/aagon.infobox}} 294 294 295 -= How to use Intune in ACMP=140 += How to use Intune in acmp = 296 296 297 -Once you have set up the ACMPIntune Connector, devices are imported from Intune intoACMP. You can use this data in queries and reports, for example. You can also send some actions to the devices throughACMP.142 +Once you have set up the acmp Intune Connector, devices are imported from Intune into acmp. You can use this data in queries and reports, for example. You can also send some actions to the devices through acmp. 298 298 299 299 == Query Actions == 300 300 ... ... @@ -313,7 +313,7 @@ 313 313 You can choose between the following actions: 314 314 315 315 {{aagon.infobox}} 316 -Note that any subsequent actions (sending notifications,retire devices, etc.) that you want to send or perform on the endpoint via Intune may be delayed. The status of the job will be shown as //Finished// in the Job Monitor as the action has been executed by ACMPand successfully passed to Intune.161 +Note that any subsequent actions (sending notifications,retire devices, etc.) that you want to send or perform on the endpoint via Intune may be delayed. The status of the job will be shown as //Finished// in the Job Monitor as the action has been executed by acmp and successfully passed to Intune. 317 317 {{/aagon.infobox}} 318 318 319 319 |**Query Actions**|(% style="width:1141px" %)**Description**

