Changes for page ACMP Intune Connector
Last modified by Sabrina V. on 2025/03/11 07:19
From version 2.1
edited by Sabrina V.
on 2025/03/11 07:19
on 2025/03/11 07:19
Change comment:
There is no comment for this version
Summary
-
Page properties (2 modified, 0 added, 0 removed)
Details
- Page properties
-
- Author
-
... ... @@ -1,1 +1,1 @@ 1 -XWiki. SV1 +XWiki.jklein - Content
-
... ... @@ -1,3 +1,11 @@ 1 +{{figureCaption}} 2 +Intune-relevante Abfrageaktionen 3 +{{/figureCaption}} 4 + 5 +{{figureCaption}} 6 +Eingabe des geheimen Clientschlüssels 7 +{{/figureCaption}} 8 + 1 1 {{aagon.priorisierung}} 2 2 160 3 3 {{/aagon.priorisierung}} ... ... @@ -25,7 +25,8 @@ 25 25 First, sign in to the [[Azure AD (Active Directory)>>https://aad.portal.azure.com/]] and navigate to Azure Active Directory in the Overview. Click the //Manage// > //Application// //Registrations// tab and create a new application registration. 26 26 27 27 {{figure}} 28 -[[image:65_Intune_App-Registrierung in der Azure AD.png||data-xwiki-image-style-alignment="center"]] 36 +(% style="text-align:center" %) 37 +[[image:65_Intune_App-Registrierung in der Azure AD.png]] 29 29 30 30 {{figureCaption}} 31 31 App registrations in the Azure AD ... ... @@ -35,7 +35,8 @@ 35 35 Enter all the necessary information: Enter a name for the application and select the accounts to support. Finish the process by clicking //Register//. 36 36 37 37 {{figure}} 38 -[[image:65_Intune_Anwendung registrieren.png||data-xwiki-image-style-alignment="center"]] 47 +(% style="text-align:center" %) 48 +[[image:65_Intune_Anwendung registrieren.png]] 39 39 40 40 {{figureCaption}} 41 41 Register application ... ... @@ -45,7 +45,8 @@ 45 45 If you now open the created application, you will see a summary of the information added. This includes the display name, the various IDs (application, object and directory ID) and details of the account types supported. 46 46 47 47 {{figure}} 48 -[[image:65_Intune_Zusammenfassung der Anwendungsinformationen.png||alt="65_Intune_Anwendung registrieren.png" data-xwiki-image-style-alignment="center"]] 58 +(% style="text-align:center" %) 59 +[[image:65_Intune_Zusammenfassung der Anwendungsinformationen.png||alt="65_Intune_Anwendung registrieren.png"]] 49 49 50 50 {{figureCaption}} 51 51 Summary of the application information ... ... @@ -57,7 +57,8 @@ 57 57 The next step is to assign the necessary permissions to the business application to access the Graph API. To do this, go to the Permissions section within the registered application (//Manage// > //API// //Permissions//). 58 58 59 59 {{figure}} 60 -[[image:65_Intune_API Berechtigungen.png||data-xwiki-image-style-alignment="center"]] 71 +(% style="text-align:center" %) 72 +[[image:65_Intune_API Berechtigungen.png]] 61 61 62 62 {{figureCaption}} 63 63 API permissions ... ... @@ -67,7 +67,8 @@ 67 67 There, click //Add Permission//. This will bring up a page where you can request the API permissions. In this step you need to select the //Microsoft Graph//. 68 68 69 69 {{figure}} 70 -[[image:65_Intune_Microsoft Graph anfordern.png||data-xwiki-image-style-alignment="center"]] 82 +(% style="text-align:center" %) 83 +[[image:65_Intune_Microsoft Graph anfordern.png]] 71 71 72 72 {{figureCaption}} 73 73 API permissions: Request Microsoft Graph ... ... @@ -81,7 +81,8 @@ 81 81 * User.Read 82 82 83 83 {{figure}} 84 -[[image:65_Intune_Delegierte Berechtigungen verteilen.png||data-xwiki-image-style-alignment="center"]] 97 +(% style="text-align:center" %) 98 +[[image:65_Intune_Delegierte Berechtigungen verteilen.png]] 85 85 86 86 {{figureCaption}} 87 87 Distribute delegated permissions ... ... @@ -101,7 +101,8 @@ 101 101 When you have selected all the permissions, click //Add Permissions//. You will see the entries in the overview. 102 102 103 103 {{figure}} 104 -[[image:65_Intune_Verteilte Berechtigungen (ohne Einwilligung).png||data-xwiki-image-style-alignment="center"]] 118 +(% style="text-align:center" %) 119 +[[image:65_Intune_Verteilte Berechtigungen (ohne Einwilligung).png]] 105 105 106 106 {{figureCaption}} 107 107 Deployed permissions (without consent) ... ... @@ -111,7 +111,8 @@ 111 111 If you have not already done so, you may need to give your consent to the permissions. To do this, click on the //Grant administrator// //consent for// //"%Your Company%//" field. This will change the status and the user permission will be granted. 112 112 113 113 {{figure}} 114 -[[image:65_Intune_Bewilligte Berechtigungen.png||data-xwiki-image-style-alignment="center"]] 129 +(% style="text-align:center" %) 130 +[[image:65_Intune_Bewilligte Berechtigungen.png]] 115 115 116 116 {{figureCaption}} 117 117 Authorised permissions ... ... @@ -137,7 +137,8 @@ 137 137 Navigate to //Certificates & Secrets// in the previously registered application. In the details, click on the //Certificates// tab and upload the previously created certificate. 138 138 139 139 {{figure}} 140 -[[image:65_Intune_Zertifikat hochladen.png||data-xwiki-image-style-alignment="center"]] 156 +(% style="text-align:center" %) 157 +[[image:65_Intune_Zertifikat hochladen.png]] 141 141 142 142 {{figureCaption}} 143 143 Upload certificate ... ... @@ -151,7 +151,8 @@ 151 151 {{/aagon.infobox}} 152 152 153 153 {{figure}} 154 -[[image:65_Intune_Hochgeladenes Zertifikat in der Azure Active Directory.png||data-xwiki-image-style-alignment="center"]] 171 +(% style="text-align:center" %) 172 +[[image:65_Intune_Hochgeladenes Zertifikat in der Azure Active Directory.png]] 155 155 156 156 {{figureCaption}} 157 157 Uploaded certificate in the Azure Active Directory ... ... @@ -163,7 +163,8 @@ 163 163 The secret client key is a string of characters used by the enterprise application as an authentication key or proof of identity when requesting the token. To do this, go to the Permissions area within the registered application (//Security// > //Permissions//) and click the Application Registration link. Navigate to //Certificates// & //Secrets//. In the details, click the //Secret Client Keys// tab and create a new key. 164 164 165 165 {{figure}} 166 -[[image:65_Intune_Neuen Clientschlüssel hinterlegen.png||data-xwiki-image-style-alignment="center"]] 184 +(% style="text-align:center" %) 185 +[[image:65_Intune_Neuen Clientschlüssel hinterlegen.png]] 167 167 168 168 {{figureCaption}} 169 169 Store new client key ... ... @@ -173,7 +173,8 @@ 173 173 When creating a new secret client key, you can configure the validity period. Note that once the validity period has expired, a new key must be created and stored in the AESB. 174 174 175 175 {{figure}} 176 -[[image:65_Intune_Geheimen Clientschlüssel hinterlegen.png||data-xwiki-image-style-alignment="center"]] 195 +(% style="text-align:center" %) 196 +[[image:65_Intune_Geheimen Clientschlüssel hinterlegen.png]] 177 177 178 178 {{figureCaption}} 179 179 Adding a secret client key ... ... @@ -195,7 +195,8 @@ 195 195 Also tick the Public API access rights box to grant access. You can now save your settings. ACMP and SICS are now connected to each other. 196 196 197 197 {{figure}} 198 -[[image:65_Intune_SICS-Verbindung_575.png||alt="65_ACMP_Einstellungen_SICS Verbindung.png" data-xwiki-image-style-alignment="center"]] 218 +(% style="text-align:center" %) 219 +[[image:65_Intune_SICS-Verbindung_575.png||alt="65_ACMP_Einstellungen_SICS Verbindung.png"]] 199 199 200 200 {{figureCaption}} 201 201 Set up SICS connection in ACMP ... ... @@ -207,7 +207,8 @@ 207 207 Now go to the AESB console. From the Dashboard, navigate to the //Products// menu item. In the overview you will find a list of all packages available for installation or updates. Select //ACMP Intune Adapter// and click //Install// either in the quick selection bar or directly in the fields. A new window will open and the installation will begin. 208 208 209 209 {{figure}} 210 -[[image:65_AESB_Übersicht des ACMP Intune Adapters in der AESB Console.png||data-xwiki-image-style-alignment="center"]] 231 +(% style="text-align:center" %) 232 +[[image:65_AESB_Übersicht des ACMP Intune Adapters in der AESB Console.png]] 211 211 212 212 {{figureCaption}} 213 213 Overview of the ACMP Intune Adapter in the AESB Console ... ... @@ -231,7 +231,8 @@ 231 231 Select //Certificate// as the authentication type. Enter the certificate to be used in the Certificate field. Only .pfx files can be uploaded. Then enter the certificate password, if available. Also enter the Application ID (Client) (the ID is used to identify the user to Intune) and the Directory ID (Tenant) (it runs under the tenant) in the fields provided. Both strings can be found in the general information of the previously registered business application on the Azure AD pages. 232 232 233 233 {{figure}} 234 -[[image:65_Eingabe der Anwendungs- und Verzeichnis-ID.png||data-xwiki-image-style-alignment="center"]] 256 +(% style="text-align:center" %) 257 +[[image:65_Eingabe der Anwendungs- und Verzeichnis-ID.png]] 235 235 236 236 {{figureCaption}} 237 237 Enter the application and directory ID ... ... @@ -239,7 +239,8 @@ 239 239 {{/figure}} 240 240 241 241 {{figure}} 242 -[[image:65_AESB_Hochladen des Zertifikats.png||data-xwiki-image-style-alignment="center"]] 265 +(% style="text-align:center" %) 266 +[[image:65_AESB_Hochladen des Zertifikats.png]] 243 243 244 244 {{figureCaption}} 245 245 Uploading the certificate ... ... @@ -255,7 +255,8 @@ 255 255 {{/aagon.infobox}} 256 256 257 257 {{figure}} 258 -[[image:65_Eingabe des geheimen Clientschlüssels.png||data-xwiki-image-style-alignment="center" height="234" width="1000"]] 282 +(% style="text-align:center" %) 283 +[[image:65_Eingabe des geheimen Clientschlüssels.png||height="234" width="1000"]] 259 259 260 260 {{figureCaption}} 261 261 Enter the secret client key ... ... @@ -265,7 +265,8 @@ 265 265 Also enter the Application ID (Client) (the ID is used to identify the user to Intune) and the Directory ID (Tenant) (under which the Tenant runs) in the fields provided. Both strings can be found in the general information of the previously registered Enterprise Application (Azure AD). 266 266 267 267 {{figure}} 268 -[[image:65_Eingabe der Anwendungs- und Verzeichnis-ID.png||data-xwiki-image-style-alignment="center"]] 293 +(% style="text-align:center" %) 294 +[[image:65_Eingabe der Anwendungs- und Verzeichnis-ID.png]] 269 269 270 270 {{figureCaption}} 271 271 Enter the application and directory ID ... ... @@ -273,7 +273,8 @@ 273 273 {{/figure}} 274 274 275 275 {{figure}} 276 -[[image:65_AESB_Eingabe der Informationen zum geheimen Clientschlüssel.png||data-xwiki-image-style-alignment="center"]] 302 +(% style="text-align:center" %) 303 +[[image:65_AESB_Eingabe der Informationen zum geheimen Clientschlüssel.png]] 277 277 278 278 {{figureCaption}} 279 279 Enter the info for the secret client key ... ... @@ -303,7 +303,8 @@ 303 303 In the query result set you will see the inventoried Client types (e.g. Clients of type Android, iOS or Windows). Select the Clients on which you want to perform an Intune action. 304 304 305 305 {{figure}} 306 -[[image:65_Abfrageaktionen_Intune relevante Abfrageaktionen.png||data-xwiki-image-style-alignment="center"]] 333 +(% style="text-align:center" %) 334 +[[image:65_Abfrageaktionen_Intune relevante Abfrageaktionen.png]] 307 307 308 308 {{figureCaption}} 309 309 Intune-relevant Query Actions ... ... @@ -335,7 +335,8 @@ 335 335 {{/aagon.infobox}} 336 336 337 337 {{figure}} 338 -[[image:65_Abfrageaktion_Ansicht der Intune Client Details.png||data-xwiki-image-style-alignment="center"]] 366 +(% style="text-align:center" %) 367 +[[image:65_Abfrageaktion_Ansicht der Intune Client Details.png]] 339 339 340 340 {{figureCaption}} 341 341 View of the Intune Client details