Scanning mobile devices from Intune with a Microsoft Cloud Services Credential is a feature introduced in Lansweeper 8.3. You will need to update your installation
if you are running a lower Lansweeper version.
In Lansweeper version 8.3, we introduced the Microsoft Cloud Service credential, which can be used to scan Intune. This credential makes full use of Modern Authentication and the Microsoft Graph API, using application permissions.
With an Intune V2 scanning target you'll be able to scan Android, iOS (iPhone and iPad) and Windows Phone mobile devices enrolled in Intune.
To scan mobile devices from Intune with a Microsoft Cloud Services Credential, make sure that:
- You've already set up your Microsoft Cloud Services application.
- You're in possession of your Microsoft Cloud Services application's Application (client) ID, Directory (tenant) ID, and Client secret or certificate. These are obtained when creating the application.
Add permissions to the Microsoft Graph application to scan Intune data
- Open your company's Azure portal and navigate to App registrations.
- Select the app you've already created and select the API permissions tab in the left-hand menu.
- On the API permissions page, click Add permission and select Microsoft Graph from the API list.
- As we are setting up the Microsoft Graph API to enforce modern authentication, you will need to add Application permissions. Start by selecting Application permissions.
- Add the DeviceManagementManagedDevices.Read.All API permission and select Save. This permission is required to scan your Intune data.
- Admin consent must still be granted. Select Grant admin consent for <organization> and click Grant in the resulting pop-up.
The added permissions should now show Granted for <organization>.
Set up Lansweeper to scan your Intune data
Add a Microsoft Cloud Service credential
- In your Lansweeper Cloud environment, go to Scanning > Credential vault > My credentials.
- Select Add new credential.
- In the pop-up, select Microsoft Cloud Service and continue.
- Fill in the fields:
- Name: name for the credential.
- Directory (tenant) ID and Application (client) ID: these are obtained when creating the Microsoft Cloud Services application.
- Authentication method: select either Client Secret or Certificate Thumbprint.
- Client Secret or Certificate Thumbprint: obtained when creating the MS Graph app in Azure.
Add an Intune V2 scanning target
- In your Lansweeper Cloud environment, navigate to Scanning > Targets.
- Select Add scanning target.
- In the pop-up, choose a scan server and select the Intune V2 scanning target.
- Enter a name and description for the new target, and select a scanning schedule.
- Select a Microsoft Cloud Service credential to assign to the Intune V2 scanning target.
- Select Save and exit, or Save target .
Was this post helpful? Leave a Kudo!
Did you have a similar issue and a different solution? Share your work in the comments below and help your fellow IT Heroes!
More questions? Browse our Quick Tech Solutions or Community Forum.
If you can't find what you're looking for, create a post in our Community Forum.