Microsoft Intune
The Microsoft Intune Connector is a software component that allows for seamless integration between Intune and Turbine, leveraging the OAuth2 protocol for secure authentication and authorization. This readme provides instructions for configuring and using the connector with Graph's OAuth2 configuration.
Prerequisites
Before you can use the Microsoft Intune Connector, you must meet the following prerequisites:
- A Microsoft Intune subscription
- An Azure AD tenant with at least one registered application
- An OAuth2 client ID and secret for your registered application
Note that if there is a Microsoft Graph API asset configured in Turbine, there is no need to create a new as long as the asset has the correct permissions.
Configurations
Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | Must start with https://login.microsoftonline.com/ and then continue with the tenant_id, and then be prepended with /oauth2/v2.0/token | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
scope | List of permission scopes for this action. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Get Detected APP
Get details on a detected APP
Endpoint
- URL: /v1.0/deviceManagement/detectedApps/{{detectedAppId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.detectedAppId | string | Required | The ID of the detected app. |
Input Example
{"path_parameters":{"detectedAppId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.value | object | Value for the parameter |
string | Response data | |
response.value.id | string | Unique identifier |
response.value.displayName | string | Name of the resource |
response.value.version | string | Value for the parameter |
response.value.sizeInByte | number | Value for the parameter |
response.value.deviceCount | number | Value for the parameter |
response.value.publisher | string | Value for the parameter |
response.value.platform | string | Value for the parameter |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"value":{"@odata.type":"#microsoft.graph.detectedApp","id":"caf60db6-0db6-caf6-b60d-f6cab60df6ca","displayName":"Display Name value","version":"Version value","sizeInByte":10,"deviceCount":11,"publisher":"Publisher value","platform":"windows"}}}
Get Detected APPs
Get properties and relationships of detected apps.
Endpoint
- URL: /v1.0/deviceManagement/detectedApps
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.value | array | Value for the parameter |
string | Response data | |
response.value.id | string | Unique identifier |
response.value.displayName | string | Name of the resource |
response.value.version | string | Value for the parameter |
response.value.sizeInByte | number | Value for the parameter |
response.value.deviceCount | number | Value for the parameter |
response.value.publisher | string | Value for the parameter |
response.value.platform | string | Value for the parameter |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"value":[{}]}}
Get User's Device Enrollment Configs
Get a User's effective device enrollment configurations
Endpoint
- URL: /beta/users/{{usersId}}/getEffectiveDeviceEnrollmentConfigurations
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.userId | string | Required | The ID of the user. |
Input Example
{"path_parameters":{"userId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.value | array | Value for the parameter |
string | Response data | |
response.value.id | string | Unique identifier |
response.value.displayName | string | Name of the resource |
response.value.description | string | Value for the parameter |
response.value.priority | number | Value for the parameter |
response.value.createdDateTime | string | Value for the parameter |
response.value.lastModifiedDateTime | string | Value for the parameter |
response.value.version | number | Value for the parameter |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"value":[{}]}}
Get User's Logged On Managed Devices
Get Managed Devices a user is logged
Endpoint
- URL: /beta/users/{{userId}}/getLoggedOnManagedDevices
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.userId | string | Required | The ID of the user. |
Input Example
{"path_parameters":{"userId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.value | array | Value for the parameter |
string | Response data | |
response.value.id | string | Unique identifier |
response.value.userId | string | Unique identifier |
response.value.deviceName | string | Name of the resource |
response.value.hardwareInformation | object | Value for the parameter |
string | Response data | |
response.value.hardwareInformation.serialNumber | string | Value for the parameter |
response.value.hardwareInformation.totalStorageSpace | number | Value for the parameter |
response.value.hardwareInformation.freeStorageSpace | number | Value for the parameter |
response.value.hardwareInformation.imei | string | Value for the parameter |
response.value.hardwareInformation.meid | string | Unique identifier |
response.value.hardwareInformation.manufacturer | string | Value for the parameter |
response.value.hardwareInformation.model | string | Value for the parameter |
response.value.hardwareInformation.phoneNumber | string | Value for the parameter |
response.value.hardwareInformation.subscriberCarrier | string | Value for the parameter |
response.value.hardwareInformation.cellularTechnology | string | Value for the parameter |
response.value.hardwareInformation.wifiMac | string | Value for the parameter |
response.value.hardwareInformation.operatingSystemLanguage | string | Value for the parameter |
response.value.hardwareInformation.isSupervised | boolean | Value for the parameter |
response.value.hardwareInformation.isEncrypted | boolean | Value for the parameter |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"value":[{}]}}
Get User's Managed APP Policies
Get a user's managed app policies
Endpoint
- URL: /beta/users/{{usersId}}/getManagedAppPolicies
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.usersId | string | Required | The ID of the user. |
Input Example
{"path_parameters":{"usersId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.value | array | Value for the parameter |
string | Response data | |
response.value.displayName | string | Name of the resource |
response.value.description | string | Value for the parameter |
response.value.createdDateTime | string | Value for the parameter |
response.value.lastModifiedDateTime | string | Value for the parameter |
response.value.id | string | Unique identifier |
response.value.version | string | Value for the parameter |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"value":[{}]}}
Get User's Managed Devices
Get a user's managed devices
Endpoint
- URL: /v1.0/users/{{userId}}/managedDevices
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.usersId | string | Required | The ID of the user. |
Input Example
{"path_parameters":{"usersId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
response.id | string | Unique identifier |
response.userId | string | Unique identifier |
response.deviceName | string | Name of the resource |
response.managedDeviceOwnerType | string | Type of the resource |
response.enrollmentDateTime | string | Time value |
response.lastSyncDateTime | string | Time value |
response.operatingSystem | string | Output field: response.operatingSystem |
response.complianceState | string | Output field: response.complianceState |
response.jailBroken | string | Output field: response.jailBroken |
response.managementAgent | string | Output field: response.managementAgent |
response.osVersion | string | Output field: response.osVersion |
response.easActivated | string | Output field: response.easActivated |
response.easDeviceId | string | Unique identifier |
response.easActivationDateTime | string | Time value |
response.azureADRegistered | string | Output field: response.azureADRegistered |
response.deviceEnrollmentType | string | Type of the resource |
response.activationLockBypassCode | string | Output field: response.activationLockBypassCode |
response.emailAddress | string | Output field: response.emailAddress |
response.azureADDeviceId | string | Unique identifier |
response.deviceRegistrationState | string | Output field: response.deviceRegistrationState |
response.deviceCategoryDisplayName | string | Name of the resource |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{"id":"id","userId":"userId","deviceName":"deviceName","managedDeviceOwnerType":"managedDeviceOwnerType","enrollmentDateTime":"enrollmentDateTime","lastSyncDateTime":"lastSyncDateTime","operatingSystem":"operatingSystem","complianceState":"complianceState","jailBroken":"jailBroken","managementAgent":"managementAgent","osVersion":"osVersion","easActivated":"easActivated","easDeviceId":"easDeviceId","easActivationDateTime":"easActivationDa...
Remote Lock
Lock action
Endpoint
- URL: /v1.0/deviceManagement/managedDevices/{{managedDeviceId}}/remoteLock
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.managedDeviceId | string | Required | The ID of the managed device. |
Input Example
{"path_parameters":{"managedDeviceId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{}}
Remove All User's Devices From Management
Remove all devices from management for a user
Endpoint
- URL: /beta/users/{{usersId}}/removeAllDevicesFromManagement
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.usersId | string | Required | The ID of the user. |
Input Example
{"path_parameters":{"usersId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{}}
Reset Passcode
Reset the passcode of a Managed Device
Endpoint
- URL: /v1.0/deviceManagement/managedDevices/{{managedDeviceId}}/resetPasscode
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.managedDeviceId | string | Required | The ID of the managed device. |
Input Example
{"path_parameters":{"managedDeviceId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
headers | object | HTTP headers for the request |
response | object | Output field: response |
Output Example
{"status_code":200,"reason":"Ok","headers":null,"response":{}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |