# Microsoft Intune MCP connector

The Microsoft Intune connector lets Claude, ChatGPT, Cursor, and the Elaichi Agent look up managed devices, lock or locate them, reset passcodes, and run remote actions, each person working inside their own Intune access with every action logged.

Source: https://elaichi.ai/connectors/msintune/

## Facts

| | |
| --- | --- |
| Application | Microsoft Intune |
| Category | Device Management |
| AI tools | 198 |
| Authentication | Connects over OAuth |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. 198 tools is past the 30-tool threshold, so clients use `search_tools` and `execute_tool` |

## What you can ask once Microsoft Intune is connected

- List non compliant managed devices enrolled this month.
- Remote lock the lost iPhone assigned to Priya.
- Which managed devices missed check in for 14 days?

## Connect Microsoft Intune in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Microsoft Intune.
2. Optionally set Share with, then press Connect.
3. Approve it in Microsoft Intune. Microsoft Intune's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Microsoft Intune tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Microsoft Intune to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Microsoft Intune to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Microsoft Intune to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Microsoft Intune to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Microsoft Intune tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Microsoft Intune through Elaichi

### Find every device a person is using

IT. Ask for all the laptops and phones enrolled under one employee and see their model, operating system, and last check-in without opening the admin center.

### Reset a locked-out passcode mid-call

Help desk. While the person is still on the phone, reset or recover the passcode on their managed device and confirm the change took.

### Lock and locate a lost laptop

Security. Remote lock a device the moment it is reported missing, request its location, and disable lost mode once it turns up on the right desk.

### Kick off a Defender scan on suspect devices

Security. Update Defender signatures and start a scan across the Windows devices flagged in an alert, then check which ones completed.

### Retire devices on someone's last day

HR. When an employee leaves, retire or wipe their company devices so corporate apps and data are removed the same afternoon.

### Reboot or clean a shared kiosk device

Operations. Restart a shared Windows or Apple device in a front desk or warehouse, sign out the active user, or run a clean before it goes to the next shift.

## Frequently asked questions

### How do I connect Microsoft Intune to Claude?

Connect Microsoft Intune in Elaichi first: pick it from the catalog and sign in with your Microsoft work account, the same way you sign in to the Intune admin center. There is no OAuth application to register and no client ID or secret to generate. Then in Claude go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and your Intune devices are available from the next message.

### Does Microsoft Intune work with ChatGPT and Cursor as well as Claude?

Yes. Once Microsoft Intune is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Intune once and every client you use picks it up, with the same access rules and the same audit log.

### What can an AI agent actually do with my Microsoft Intune devices?

An agent can list your managed devices, pull up the details of one device, and update its record. It can also run the day-to-day remote actions you would otherwise click through in the Intune admin center: lock, locate, reboot, shut down, sync, reset or recover a passcode, retire or wipe a device, run a Defender scan or signature update, sign a user out of a shared Apple device, and bypass an activation lock. Because Microsoft Intune exposes a long list of actions, short concrete asks such as "lock Priya's Surface" work better than long paragraphs.

### Does connecting Microsoft Intune give the AI access to every device in my tenant?

No. When you connect Microsoft Intune through Elaichi the AI works as you, so it can only see and act on the devices your own Intune role allows. Elaichi can narrow that further, for example limiting a help desk toolbox to lookups and passcode resets, but it can never widen access beyond what your Microsoft account already has.

### Can my team share one Microsoft Intune connection?

Yes. One administrator connects Microsoft Intune in Elaichi and shares the connection with a team, so nobody else has to handle a Microsoft credential or admin role. Each teammate still signs in to Claude, ChatGPT, or Cursor as themselves, so the audit log records exactly which person locked, wiped, or rebooted a device.

### Can I stop an agent from wiping or deleting devices in Microsoft Intune?

Yes. Restrictions in Elaichi apply per action, so you can allow an agent to list and locate Microsoft Intune devices while blocking wipe, retire, delete, and shut down. A blocked action is never advertised to Claude, ChatGPT, or any other client, so no prompt can reach it, however it is worded.

### What happens to a Microsoft Intune connection when someone leaves?

When you offboard a person in Elaichi their access to the Microsoft Intune connection ends immediately, in every client at once. If they connected Intune on behalf of a team, the shared connection keeps working for everyone else. Disconnecting Microsoft Intune once in Elaichi removes it from Claude, ChatGPT, Cursor, and the Elaichi Agent together.

## All 198 Microsoft Intune tools

Every tool below is callable through https://api.elaichi.ai/mcp once Microsoft Intune is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Microsoft Intune managed devices** (List). List managed devices enrolled in Microsoft Intune. Returns: @odata.type, id, userId, deviceName, managedDeviceOwnerType, deviceActionResults, managementState, enrolledDateTime, lastSyncDateTime, operatingSystem, complianceState, jailBroken, managementAgent, osVersion, easActivated, easDeviceId, easActivationDateTime, azureADRegistered, deviceEnrollmentType, activationLockBypassCode, emailAddress,…
- **Get single Microsoft Intune managed device by ID** (Get). Get a single managed device by id in Microsoft Intune. Returns: @odata.type, id, userId, deviceName, managedDeviceOwnerType, deviceActionResults, managementState, enrolledDateTime, lastSyncDateTime, operatingSystem, complianceState, jailBroken, managementAgent, osVersion, easActivated, easDeviceId, easActivationDateTime, azureADRegistered, deviceEnrollmentType, activationLockBypassCode,…
- **Create a Microsoft Intune managed device** (Create). Create a new managed device in Microsoft Intune. Returns: @odata.type, id, userId, deviceName, managedDeviceOwnerType, deviceActionResults, managementState, enrolledDateTime, lastSyncDateTime, operatingSystem, complianceState, jailBroken, managementAgent, osVersion, easActivated, easDeviceId, easActivationDateTime, azureADRegistered, deviceEnrollmentType, activationLockBypassCode, emailAddress,…
- **Delete a Microsoft Intune managed device by ID** (Delete). Delete a managed device in Microsoft Intune by id. Returns an empty 204 response on success. Required: id. The API requires an active Intune license for the tenant.
- **Update a Microsoft Intune managed device by ID** (Update). Update a managed device's properties in Microsoft Intune. Returns the updated managedDevice object including id, deviceName, managedDeviceOwnerType, complianceState, operatingSystem, osVersion, enrolledDateTime, and lastSyncDateTime. Required: id. Requires an active Intune license for the tenant.
- **Microsoft Intune managed devices retire** (Action). Retire a managed device in Microsoft Intune by initiating a retire action on the specified device. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices wipe** (Action). Wipe a managed device in Microsoft Intune, optionally preserving enrollment data, user data, and eSIM data plan. Returns an empty 204 response on success. Required: managed_device_id. Optional body parameters control retention of enrollment data, user data, eSIM plans, Mac unlock code, and obliteration behavior.
- **Microsoft Intune managed devices reset passcode** (Action). Reset the passcode on a managed device in Microsoft Intune by initiating a resetPasscode action on the specified device. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices remote lock** (Action). Remotely lock a managed device in msintune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices request remote assistance** (Action). Request remote assistance for a managed device in msintune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices disable lost mode** (Disable). Disable lost mode on a managed Intune device. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices locate device** (Action). Locate a managed Intune device, triggering a request for the device to report its location. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices bypass activation lock** (Action). Bypass the activation lock on a managed Intune device. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices reboot now** (Action). Reboot a managed Intune device immediately. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices shut down** (Action). Shut down a managed Intune device. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices recover passcode** (Action). Recover the passcode of a managed device in Microsoft Intune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices clean windows device** (Action). Clean a Windows managed device in Microsoft Intune, specifying whether to preserve user data. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices logout shared apple device active user** (Action). Log out the active user from a shared Apple managed device in Microsoft Intune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices delete user from shared apple device** (Delete). Delete a specific user from a shared Apple managed device in Microsoft Intune by user principal name. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices sync device** (Sync). Trigger a device sync for a managed device in Microsoft Intune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices windows defender scan** (Action). Trigger a Windows Defender scan on a managed device in Microsoft Intune. Pass quickScan as true for a quick scan or false for a full scan. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices windows defender update signatures** (Update). Trigger a Windows Defender signature update on a managed device in Microsoft Intune. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices update windows device account** (Update). Update the Windows device account on a managed device in Microsoft Intune. Accepts account credentials, password rotation, calendar sync, and Exchange server settings via the updateWindowsDeviceAccountActionParameter. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices disable** (Disable). Disable a managed device in Microsoft Intune by managed_device_id. Returns an empty 204 response on success. Required: managed_device_id.
- **Microsoft Intune managed devices execute action** (Execute). Execute a remote action on one or more managed devices in Microsoft Intune. Returns the value object containing successfulDeviceIds, failedDeviceIds, notFoundDeviceIds, and notSupportedDeviceIds. Required: actionName, deviceIds.
- **Managed devices initiate on demand proactive remediation** (Action). Initiate an on-demand proactive remediation on a Microsoft Intune managed device. Returns an empty 204 response on success. Required: managed_device_id, scriptPolicyId.
- **Managed devices send custom notification to company portal** (Send). Send a custom notification to the Company Portal app on Microsoft Intune managed devices. Returns an empty 204 response on success. Required: notificationTitle, notificationBody.
- **List all Microsoft Intune detected apps** (List). List detected apps discovered by Microsoft Intune. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform.
- **Get single Microsoft Intune detected app by ID** (Get). Get a single detected app in Microsoft Intune by id. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform, value.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform, value. Required: id.
- **Create a Microsoft Intune detected app** (Create). Create a new detected app in Microsoft Intune. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform.
- **Delete a Microsoft Intune detected app by ID** (Delete). Delete a detected app in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune detected app by ID** (Update). Update a detected app in Microsoft Intune by id. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform, value. Required: id.
- **List all Microsoft Intune device compliance policies** (List). List device compliance policies in Microsoft Intune. Returns: @odata.type, id, createdDateTime, description, lastModifiedDateTime, displayName, version.
- **Get single Microsoft Intune device compliance policy by ID** (Get). Get a single device compliance policy in Microsoft Intune by id. Returns: @odata.type, id, createdDateTime, description, lastModifiedDateTime, displayName, version, value. Required: id.
- **Microsoft Intune device compliance policies assign** (Assign). Assign a device compliance policy in Microsoft Intune to specified targets. Returns a value collection of deviceCompliancePolicyAssignment objects, each including @odata.type, id, and target with targetType and entraObjectId. Required: device_compliance_policy_id, assignments.
- **Microsoft Intune device compliance policies schedule actions for rules** (Action). Schedule compliance actions for rules on a device compliance policy in Microsoft Intune. Returns an empty 204 response on success. Required: device_compliance_policy_id, deviceComplianceScheduledActionForRules.
- **List all Microsoft Intune device configurations** (List). List device configurations in Microsoft Intune. Returns: @odata.type, id, lastModifiedDateTime, createdDateTime, description, displayName, version.
- **Get single Microsoft Intune device configuration by ID** (Get). Get a single device configuration in Microsoft Intune by id. Returns: @odata.type, id, lastModifiedDateTime, createdDateTime, description, displayName, version, value. Required: id.
- **Microsoft Intune device configurations assign** (Assign). Assign a device configuration in Microsoft Intune to specified targets by providing a collection of assignments. Returns: value. Required: device_configuration_id, assignments.
- **Microsoft Intune device configurations get oma setting plain text value** (Get). Retrieve the plain text value of an OMA setting for a device configuration in Microsoft Intune. Returns: value. Required: device_configuration_id, secretReferenceValueId.
- **List all Microsoft Intune mobile apps** (List). List mobile apps managed in Microsoft Intune. Returns a collection of mobileApp objects including id, displayName, description, publisher, largeIcon, createdDateTime, lastModifiedDateTime, isFeatured, publishingState, and more.
- **Get single Microsoft Intune mobile app by ID** (Get). Get a single mobile app in Microsoft Intune by id. Returns the mobileApp object including id, displayName, description, publisher, largeIcon, createdDateTime, lastModifiedDateTime, isFeatured, publishingState, and more. Required: id.
- **Microsoft Intune mobile apps assign** (Assign). Assign a mobile app in Microsoft Intune to target groups with a specified install intent and assignment settings. Returns an empty 204 response on success. Required: mobile_app_id.
- **Create a Microsoft Intune mobile app** (Create). Create a new Win32 LOB app in Microsoft Intune. Returns the created win32LobApp object including id, displayName, description, publisher, createdDateTime, lastModifiedDateTime, publishingState, installCommandLine, applicableArchitectures, rules, installExperience, returnCodes, msiInformation, and more.
- **Microsoft Intune mobile apps enable applicable architectures** (Enable). Enable applicable architectures for a Win32 LOB app in Microsoft Intune. Accepts an applicableArchitectures value in the request body. Returns an empty 204 response on success. Required: mobile_app_id.
- **List all Microsoft Intune mobile app assignments** (List). List the group assignments for a Microsoft Intune mobile app. Returns each assignment's id, intent (available, required, uninstall, or availableWithoutEnrollment), target (the assigned group), and settings (per-platform install settings). Required: mobile_app_id.
- **Get single Microsoft Intune mobile app assignment by ID** (Get). Get a single group assignment for a Microsoft Intune mobile app by id. Returns: id, intent, target, settings. Required: mobile_app_id, id.
- **Create a Microsoft Intune mobile app assignment** (Create). Create a new group assignment for a Microsoft Intune mobile app. Returns the created assignment: id, intent, target, settings (201 Created). Required: mobile_app_id, intent, target.
- **Delete a Microsoft Intune mobile app assignment by ID** (Delete). Delete a group assignment for a Microsoft Intune mobile app. Returns an empty 204 response on success. Required: mobile_app_id, id.
- **Update a Microsoft Intune mobile app assignment by ID** (Update). Update an existing group assignment for a Microsoft Intune mobile app. Returns the updated assignment: id, intent, target, settings (200 OK). Required: mobile_app_id, id.
- **List all Microsoft Intune managed app protections** (List). List managed app protection policies in Microsoft Intune. Returns: @odata.type, displayName, description, createdDateTime, lastModifiedDateTime, id, version, periodOfflineBeforeAccessCheck, periodOnlineBeforeAccessCheck, allowedInboundDataTransferSources, allowedOutboundDataTransferDestinations, organizationalCredentialsRequired, allowedOutboundClipboardSharingLevel, dataBackupBlocked,…
- **Get single Microsoft Intune managed app protection by ID** (Get). Get a single managed app protection policy in Microsoft Intune by id. Returns: @odata.type, displayName, description, createdDateTime, lastModifiedDateTime, id, version, periodOfflineBeforeAccessCheck, periodOnlineBeforeAccessCheck, allowedInboundDataTransferSources, allowedOutboundDataTransferDestinations, organizationalCredentialsRequired, allowedOutboundClipboardSharingLevel,…
- **Microsoft Intune managed app protections target apps** (Action). Target apps for a managed app protection policy in Microsoft Intune by assigning a collection of managed mobile apps. Returns an empty 204 response on success. Required: managed_app_policy_id, apps.
- **List all Microsoft Intune mobile threat defense connectors** (List). List all mobile threat defense connectors configured in Microsoft Intune. Returns: @odata.type, id, lastHeartbeatDateTime, partnerState, androidMobileApplicationManagementEnabled, iosMobileApplicationManagementEnabled, androidEnabled, iosEnabled, windowsEnabled, androidDeviceBlockedOnMissingPartnerData, iosDeviceBlockedOnMissingPartnerData, windowsDeviceBlockedOnMissingPartnerData,…
- **Get single Microsoft Intune mobile threat defense connector by ID** (Get). Get a single mobile threat defense connector in Microsoft Intune by id. Returns: @odata.type, id, lastHeartbeatDateTime, partnerState, androidMobileApplicationManagementEnabled, iosMobileApplicationManagementEnabled, androidEnabled, iosEnabled, windowsEnabled, androidDeviceBlockedOnMissingPartnerData, iosDeviceBlockedOnMissingPartnerData, windowsDeviceBlockedOnMissingPartnerData,…
- **Create a Microsoft Intune mobile threat defense connector** (Create). Create a new mobile threat defense connector in Microsoft Intune. Returns the created connector including id, lastHeartbeatDateTime, partnerState, androidEnabled, iosEnabled, windowsEnabled, and partner compliance and MAM evaluation settings.
- **Delete a Microsoft Intune mobile threat defense connector by ID** (Delete). Delete a mobile threat defense connector in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune mobile threat defense connector by ID** (Update). Update the properties of a mobile threat defense connector in Microsoft Intune by id. Returns the updated connector including id, lastHeartbeatDateTime, partnerState, androidEnabled, iosEnabled, windowsEnabled, and partner compliance and MAM evaluation settings. Required: id.
- **List all Microsoft Intune windows autopilot device identities** (List). List Windows Autopilot device identities in Microsoft Intune. Returns: @odata.type, id, groupTag, purchaseOrderIdentifier, serialNumber, productKey, manufacturer, model, enrollmentState, lastContactedDateTime, addressableUserName, userPrincipalName, resourceName, skuNumber, systemFamily, azureActiveDirectoryDeviceId, managedDeviceId, displayName.type, id, groupTag, purchaseOrderIdentifier,…
- **Get single Microsoft Intune windows autopilot device identity by ID** (Get). Get a single Windows Autopilot device identity by id in Microsoft Intune. Returns: @odata.type, id, groupTag, purchaseOrderIdentifier, serialNumber, productKey, manufacturer, model, enrollmentState, lastContactedDateTime, addressableUserName, userPrincipalName, resourceName, skuNumber, systemFamily, azureActiveDirectoryDeviceId, managedDeviceId, displayName, value.type, id, groupTag,…
- **Create a Microsoft Intune windows autopilot device identity** (Create). Create a new Windows Autopilot device identity in Microsoft Intune. Returns: @odata.type, id, groupTag, purchaseOrderIdentifier, serialNumber, productKey, manufacturer, model, enrollmentState, lastContactedDateTime, addressableUserName, userPrincipalName, resourceName, skuNumber, systemFamily, azureActiveDirectoryDeviceId, managedDeviceId, displayName.
- **Delete a Microsoft Intune windows autopilot device identity by ID** (Delete). Delete a Windows Autopilot device identity by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Windows autopilot device identities assign user to device** (Assign). Assign a user to a Windows Autopilot device in Microsoft Intune by providing the user principal name and addressable user name. Returns an empty 204 response on success. Required: windows_autopilot_device_identity_id.
- **Windows autopilot device identities unassign user from device** (Action). Unassign the user from a Windows Autopilot device in msintune. Returns an empty 204 response on success. Required: windows_autopilot_device_identity_id.
- **Windows autopilot device identities update device properties** (Update). Update properties on a Windows Autopilot device in msintune, including user principal name, addressable user name, group tag, and display name. Returns an empty 204 response on success. Required: windows_autopilot_device_identity_id.
- **Microsoft Intune windows autopilot device identities delete devices** (Delete). Delete Windows Autopilot devices by serial numbers in msintune. Returns a collection of deleted device state objects including serialNumber, deviceRegistrationId, deletionState, and errorMessage. Required: serialNumbers.
- **List all Microsoft Intune group policy configurations** (List). List group policy configurations in Microsoft Intune. Returns: @odata.type, id, createdDateTime, description, displayName, lastModifiedDateTime, version.
- **Get single Microsoft Intune device compliance setting state by ID** (Get). Get a single device compliance setting state from Microsoft Intune, nested under a device compliance policy setting state summary. Returns: @odata.type, id, setting, settingName, deviceId, deviceName, userId, userEmail, userName, userPrincipalName, deviceModel, state, complianceGracePeriodExpirationDateTime, value. Required: device_compliance_policy_setting_state_summary_id, id. Requires an…
- **List all Microsoft Intune managed apps** (List). List managed apps in Microsoft Intune, returning properties and relationships of each managedApp object. Returns: @odata.type, id, displayName, description, publisher, largeIcon, createdDateTime, lastModifiedDateTime, isFeatured, privacyInformationUrl, informationUrl, owner, developer, notes, publishingState, appAvailability, version.type, id, displayName, description, publisher, largeIcon,…
- **Create a Microsoft Intune android device owner compliance policy** (Create). Create an Android Device Owner compliance policy in Microsoft Intune by posting to the device compliance policies endpoint. Returns the created policy including id, displayName, description, version, passwordRequired, deviceThreatProtectionEnabled, passwordRequiredType, storageRequireEncryption, and other compliance and security settings. Required: @odata.type (set to…
- **Create a Microsoft Intune windows 10 custom configuration** (Create). Create a new Windows 10 custom configuration in Microsoft Intune with custom OMA settings. Returns: @odata.type, id, lastModifiedDateTime, createdDateTime, description, displayName, version, omaSettings. Required: @odata.type, displayName. The omaSettings collection can contain a maximum of 1000 elements.
- **List all Microsoft Intune device management scripts** (List). List device management scripts in Microsoft Intune. Returns: id, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime, runAsAccount, enforceSignatureCheck, fileName, roleScopeTagIds, runAs32Bit.
- **Get single Microsoft Intune device management script by ID** (Get). Get a single device management script in Microsoft Intune by id. Returns: id, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime, runAsAccount, enforceSignatureCheck, fileName, roleScopeTagIds, runAs32Bit. Required: id.
- **Create a Microsoft Intune device management script** (Create). Create a new device management script in Microsoft Intune. Returns the created script including id, displayName, description, scriptContent, fileName, runAsAccount, enforceSignatureCheck, runAs32Bit, roleScopeTagIds, createdDateTime, and lastModifiedDateTime.
- **Delete a Microsoft Intune device management script by ID** (Delete). Delete a device management script in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune device management script by ID** (Update). Update the properties of a device management script in Microsoft Intune by id. Returns the updated script including id, displayName, description, scriptContent, fileName, runAsAccount, enforceSignatureCheck, runAs32Bit, roleScopeTagIds, createdDateTime, and lastModifiedDateTime. Required: id.
- **Microsoft Intune device management scripts assign** (Assign). Assign a Microsoft Intune device management script to target groups by providing a collection of assignment objects. Returns an empty 204 response on success. Required: device_management_script_id.
- **List all Microsoft Intune role scope tags** (List). List role scope tags in Microsoft Intune. Returns: @odata.type, id, displayName, description, isBuiltIn.type for each tag.
- **Get single Microsoft Intune role scope tag by ID** (Get). Get a single role scope tag in Microsoft Intune by id. Returns: @odata.type, id, displayName, description, isBuiltIn, value.type. Required: id.
- **Create a Microsoft Intune role scope tag** (Create). Create a new role scope tag in Microsoft Intune. Returns: @odata.type, id, displayName, description, isBuiltIn.type. Required: displayName.
- **Delete a Microsoft Intune role scope tag by ID** (Delete). Delete a role scope tag in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune role scope tag by ID** (Update). Update the properties of a role scope tag in Microsoft Intune by id. Returns: @odata.type, id, displayName, description, isBuiltIn.type. Required: id.
- **Microsoft Intune role scope tags assign** (Assign). Assign a role scope tag in Microsoft Intune to specified assignment targets. Returns a collection of roleScopeTagAutoAssignment objects, each containing id and target. Required: role_scope_tag_id.
- **List all Microsoft Intune device management intents** (List). List device management intents in Microsoft Intune. Returns: @odata.type, id, displayName, description, isAssigned, isMigratingToConfigurationPolicy, lastModifiedDateTime, templateId, roleScopeTagIds.
- **Get single Microsoft Intune device management intent by ID** (Get). Get a single device management intent by id in Microsoft Intune. Returns: @odata.type, id, displayName, description, isAssigned, isMigratingToConfigurationPolicy, lastModifiedDateTime, templateId, roleScopeTagIds. Required: id.
- **Create a Microsoft Intune device management intent** (Create). Create a new device management intent in Microsoft Intune. Returns the created intent including id, displayName, description, isAssigned, templateId, and roleScopeTagIds.
- **Delete a Microsoft Intune device management intent by ID** (Delete). Delete a device management intent by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune device management intent by ID** (Update). Update a device management intent by id in Microsoft Intune. Returns the updated intent including id, displayName, description, isAssigned, templateId, and roleScopeTagIds. Required: id.
- **Microsoft Intune device management intents update settings** (Update). Update settings for a device management intent in msintune by applying a new collection of settings. Returns an empty 204 response on success. Required: device_management_intent_id.
- **Microsoft Intune device management intents migrate to template** (Action). Migrate a device management intent in msintune from its current template to a new template. Returns an empty 204 response on success. Required: device_management_intent_id.
- **Microsoft Intune device management intents create copy** (Create). Create a copy of an existing device management intent in Microsoft Intune. Returns the copied deviceManagementIntent object including id, displayName, description, isAssigned, isMigratingToConfigurationPolicy, lastModifiedDateTime, templateId, and roleScopeTagIds. Required: device_management_intent_id.
- **Microsoft Intune device management intents assign** (Assign). Assign a Microsoft Intune device management intent (a settings catalog / template-based configuration profile) to one or more groups. Returns an empty 204 response on success. Required: device_management_intent_id, assignments.
- **Microsoft Intune device management intents compare** (Action). Compare a Microsoft Intune device management intent's current settings against a template's settings. Returns a 200 OK with one deviceManagementSettingComparison entry per compared setting: id, displayName, definitionId, currentValueJson, newValueJson, comparisonResult. Required: device_management_intent_id, templateId.
- **Microsoft Intune device management intents get customized settings** (Get). Get the settings on a Microsoft Intune device management intent that have been customized away from their default values. Returns a 200 OK with one deviceManagementIntentCustomizedSetting entry per customized setting: definitionId, defaultJson, customizedJson. Required: device_management_intent_id.
- **List all Microsoft Intune reusable policy settings** (List). List device management reusable policy settings in Microsoft Intune. Returns: id, displayName, description, settingDefinitionId, settingInstance, createdDateTime, lastModifiedDateTime, version, referencingConfigurationPolicyCount.
- **Get single Microsoft Intune reusable policy setting by ID** (Get). Get a single device management reusable policy setting in Microsoft Intune by id. Returns: id, displayName, description, settingDefinitionId, settingInstance, createdDateTime, lastModifiedDateTime, version, referencingConfigurationPolicyCount. Required: id.
- **Create a Microsoft Intune reusable policy setting** (Create). Create a new device management reusable policy setting in Microsoft Intune. Returns the created setting object including id, displayName, description, settingDefinitionId, settingInstance, createdDateTime, lastModifiedDateTime, version, and referencingConfigurationPolicyCount.
- **Delete a Microsoft Intune reusable policy setting by ID** (Delete). Delete a deviceManagementReusablePolicySetting in msintune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune reusable policy setting by ID** (Update). Update the properties of a deviceManagementReusablePolicySetting in msintune by id. Returns: id, displayName, description, settingDefinitionId, settingInstance, createdDateTime, lastModifiedDateTime, version, referencingConfigurationPolicyCount. Required: id.
- **Microsoft Intune reusable policy settings clone** (Action). Clone a Microsoft Intune device management reusable policy setting, producing a new copy of the original. Returns the cloned setting including id, displayName, description, settingDefinitionId, settingInstance, createdDateTime, lastModifiedDateTime, version, and referencingConfigurationPolicyCount. Required: device_management_reusable_policy_setting_id.
- **List all Microsoft Intune intune branding profiles** (List). List Intune branding profiles in Microsoft Intune. Returns: @odata.type, id, profileName, profileDescription, isDefaultProfile, createdDateTime, lastModifiedDateTime, displayName, themeColor, showLogo, showDisplayNameNextToLogo, themeColorLogo, lightBackgroundLogo, landingPageCustomizedImage, contactITName, contactITPhoneNumber, contactITEmailAddress, contactITNotes, onlineSupportSiteUrl,…
- **Get single Microsoft Intune intune branding profile by ID** (Get). Get a single Intune branding profile by id in Microsoft Intune. Returns: id, error. Required: id.
- **Create a Microsoft Intune intune branding profile** (Create). Create a new Intune branding profile. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform.
- **Delete a Microsoft Intune intune branding profile by ID** (Delete). Delete an Intune branding profile by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune intune branding profile by ID** (Update). Update the properties of an Intune branding profile by id. Returns: id, error. Required: id.
- **Microsoft Intune intune branding profiles assign** (Assign). Assign group assignments to an Intune branding profile in Microsoft Intune. The request body contains an assignments collection of intuneBrandingProfileAssignment objects, each with a target group. Returns an empty 204 response on success. Required: intune_branding_profile_id.
- **List all Microsoft Intune managed device cleanup rules** (List). List managed device cleanup rules in Microsoft Intune. Returns: @odata.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.
- **Get single Microsoft Intune managed device cleanup rule by ID** (Get). Get a single managed device cleanup rule in Microsoft Intune by id. Returns: @odata.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays. Required: id.
- **Create a Microsoft Intune managed device cleanup rule** (Create). Create a new managed device cleanup rule in Microsoft Intune. Returns: @odata.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.
- **Delete a Microsoft Intune managed device cleanup rule by ID** (Delete). Delete a managed device cleanup rule in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune managed device cleanup rule by ID** (Update). Update the properties of a managed device cleanup rule in Microsoft Intune by id. Returns: @odata.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays.type, id, displayName, description, deviceCleanupRulePlatformType, lastModifiedDateTime, deviceInactivityBeforeRetirementInDays. Required: id.
- **List all Microsoft Intune device custom attribute shell scripts** (List). List device custom attribute shell scripts in Microsoft Intune. Returns: @odata.type, id, customAttributeName, customAttributeType, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime, runAsAccount, fileName, roleScopeTagIds.type, id, customAttributeName, customAttributeType, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime, runAsAccount,…
- **Get single Microsoft Intune device custom attribute shell script by ID** (Get). Get a single device custom attribute shell script by id in Microsoft Intune. Returns: @odata.type, id, customAttributeName, customAttributeType, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime, runAsAccount, fileName, roleScopeTagIds.type, id, customAttributeName, customAttributeType, displayName, description, scriptContent, createdDateTime, lastModifiedDateTime,…
- **Create a Microsoft Intune device custom attribute shell script** (Create). Create a new device custom attribute shell script in Microsoft Intune. Returns the created script object including id, displayName, customAttributeName, customAttributeType, scriptContent, runAsAccount, and other script properties.
- **Delete a Microsoft Intune device custom attribute shell script by ID** (Delete). Delete a device custom attribute shell script by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune device custom attribute shell script by ID** (Update). Update the properties of a device custom attribute shell script by id in Microsoft Intune. Returns the updated script object including id, displayName, customAttributeName, customAttributeType, scriptContent, runAsAccount, and other script properties. Required: id.
- **Microsoft Intune device custom attribute shell scripts assign** (Assign). Assign a device custom attribute shell script to target groups in msintune. The request body contains an assignments array of deviceManagementScriptAssignment objects specifying the target groups. Returns an empty 204 response on success. Required: device_custom_attribute_shell_script_id.
- **List all Microsoft Intune managed device encryption states** (List). List managed device encryption states in Microsoft Intune. Returns: @odata.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion, deviceName, encryptionReadinessState, encryptionState, encryptionPolicySettingState, advancedBitLockerStates, fileVaultStates, policyDetails.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion, deviceName,…
- **Get single Microsoft Intune managed device encryption state by ID** (Get). Get a single managed device encryption state by id in Microsoft Intune. Returns: @odata.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion, deviceName, encryptionReadinessState, encryptionState, encryptionPolicySettingState, advancedBitLockerStates, fileVaultStates, policyDetails.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion, deviceName,…
- **Create a Microsoft Intune managed device encryption state** (Create). Create a new managed device encryption state in Microsoft Intune. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform.
- **Delete a Microsoft Intune managed device encryption state by ID** (Delete). Delete a managed device encryption state by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune managed device encryption state by ID** (Update). Update the properties of a managed device encryption state by id in Microsoft Intune. Returns: @odata.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion, deviceName, encryptionReadinessState, encryptionState, encryptionPolicySettingState, advancedBitLockerStates, fileVaultStates, policyDetails.type, id, userPrincipalName, deviceType, osVersion, tpmSpecificationVersion,…
- **List all Microsoft Intune user experience analytics device scopes** (List). List user experience analytics device scope configurations in Microsoft Intune. Returns: @odata.type, id, deviceScopeName, ownerId, isBuiltIn, enabled, status, parameter, operator, valueObjectId, value, createdDateTime, lastModifiedDateTime.
- **Get single Microsoft Intune user experience analytics device scope by ID** (Get). Get a single user experience analytics device scope configuration in Microsoft Intune by id. Returns the full device scope object including id, deviceScopeName, ownerId, isBuiltIn, enabled, status, parameter, operator, valueObjectId, value, createdDateTime, and lastModifiedDateTime. Required: id.
- **User experience analytics device scopes trigger device scope act** (Action). Trigger an action (such as re-evaluation) on a Microsoft Intune user experience analytics device scope. Returns a 200 OK with a deviceScopeActionResult indicating the outcome: deviceScopeAction, deviceScopeId, status, and failedMessage if it failed. Required: actionName, deviceScopeId.
- **List all Microsoft Intune operation approval policies** (List). List operation approval policies in Microsoft Intune. Returns: @odata.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds.
- **Get single Microsoft Intune operation approval policy by ID** (Get). Get a single operation approval policy by id in Microsoft Intune. Returns: @odata.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds. Required: id.
- **Create a Microsoft Intune operation approval policy** (Create). Create a new operation approval policy in Microsoft Intune. Returns: @odata.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds, version, sizeInByte, deviceCount, publisher, platform.type, id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, approverGroupIds. Required: displayName, policySet,…
- **Delete a Microsoft Intune operation approval policy by ID** (Delete). Delete an operation approval policy in Microsoft Intune by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune operation approval policy by ID** (Update). Update the properties of an operation approval policy in Microsoft Intune by id. Returns the updated policy object including id, displayName, description, lastModifiedDateTime, policyType, policyPlatform, policySet, and approverGroupIds. Required: id.
- **Operation approval policies retrieve approvable operations** (Action). Retrieve the approvable operations for a specific operation approval policy in Microsoft Intune. Returns a collection of operationApprovalPolicySet objects including @odata.type, policyType, and policyPlatform. Required: operation_approval_policy_id.
- **Operation approval policies retrieve operations requiring approv** (Action). Retrieve the operations requiring approval for a specific operation approval policy in Microsoft Intune. Returns a collection of operationApprovalPolicySet objects including @odata.type, policyType, and policyPlatform. Required: operation_approval_policy_id.
- **List all Microsoft Intune windows driver update profiles** (List). List Windows driver update profiles in Microsoft Intune. Returns: @odata.type, id, displayName, description, approvalType, deviceReporting, newUpdates, deploymentDeferralInDays, createdDateTime, lastModifiedDateTime, roleScopeTagIds, inventorySyncStatus.type, id, displayName, description, approvalType, deviceReporting, newUpdates, deploymentDeferralInDays, createdDateTime, lastModifiedDateTime,…
- **Get single Microsoft Intune windows driver update profile by ID** (Get). Get a single Windows driver update profile by id in Microsoft Intune. Returns: @odata.type, id, displayName, version, sizeInByte, deviceCount, publisher, platform. Required: id.
- **Create a Microsoft Intune windows driver update profile** (Create). Create a new Windows driver update profile in Microsoft Intune. Returns the created profile including id, displayName, description, approvalType, deviceReporting, newUpdates, deploymentDeferralInDays, createdDateTime, lastModifiedDateTime, roleScopeTagIds, and inventorySyncStatus. Required: displayName.
- **Delete a Microsoft Intune windows driver update profile by ID** (Delete). Delete a Windows driver update profile by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune windows driver update profile by ID** (Update). Update the properties of a Windows driver update profile by id in Microsoft Intune. Returns the updated profile including id, displayName, description, approvalType, deviceReporting, newUpdates, deploymentDeferralInDays, createdDateTime, lastModifiedDateTime, roleScopeTagIds, and inventorySyncStatus. Required: id.
- **Microsoft Intune windows driver update profiles assign** (Update). Assign group assignments to a Windows driver update profile in Microsoft Intune. Returns an empty 204 response on success. Required: windows_driver_update_profile_id.
- **Microsoft Intune windows driver update profiles execute action** (Update). Execute a bulk action (approve, decline, or schedule) on drivers within a Microsoft Intune Windows driver update profile's inventory. Returns a 200 OK with a bulkDriverActionResult listing which driver ids succeeded, failed, or were not found. Required: windows_driver_update_profile_id, actionName, driverIds.
- **Microsoft Intune windows driver update profiles sync inventory** (Update). Sync the driver inventory of a Windows Driver Update Profile in Microsoft Intune. Returns an empty 204 response on success. Required: windows_driver_update_profile_id.
- **List all Microsoft Intune dep onboarding settings** (List). List DEP onboarding settings in Microsoft Intune. Returns a collection of depOnboardingSetting objects including id, appleIdentifier, tokenName, tokenType, tokenExpirationDateTime, syncedDeviceCount, and lastModifiedDateTime.
- **Get single Microsoft Intune dep onboarding setting by ID** (Get). Get a single DEP onboarding setting by id in Microsoft Intune. Returns the full depOnboardingSetting object including id, appleIdentifier, tokenName, tokenType, tokenExpirationDateTime, lastModifiedDateTime, and syncedDeviceCount. Required: id.
- **Create a Microsoft Intune dep onboarding setting** (Create). Create a new DEP onboarding setting in Microsoft Intune. Returns the created depOnboardingSetting object including id, appleIdentifier, tokenName, tokenType, tokenExpirationDateTime, and syncedDeviceCount.
- **Delete a Microsoft Intune dep onboarding setting by ID** (Delete). Delete a DEP onboarding setting by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune dep onboarding setting by ID** (Update). Update the properties of a DEP onboarding setting by id in Microsoft Intune. Returns the updated depOnboardingSetting object including id, appleIdentifier, tokenName, tokenType, tokenExpirationDateTime, and syncedDeviceCount. Required: id.
- **Microsoft Intune dep onboarding settings get encryption public key** (Get). Get the encryption public key for a DEP onboarding setting in Microsoft Intune, used to encrypt the Apple Device Enrollment Program token. Returns: value. Required: dep_onboarding_setting_id.
- **Microsoft Intune dep onboarding settings generate encryption public key** (Generate). Generate a new encryption public key for a DEP onboarding setting in Microsoft Intune, used to encrypt the Apple Device Enrollment Program token. Returns: value. Required: dep_onboarding_setting_id.
- **Microsoft Intune dep onboarding settings upload dep token** (Upload). Upload a new Device Enrollment Program (DEP) token to an existing DEP onboarding setting in Microsoft Intune. Returns an empty 204 response on success. Required: dep_onboarding_setting_id.
- **Dep onboarding settings sync with apple device enrollment progra** (Sync). Sync an Intune DEP onboarding setting with the Apple Device Enrollment Program to pull the latest devices from Apple DEP. Returns an empty 204 response on success. Required: dep_onboarding_setting_id.
- **List all Microsoft Intune enrollment profiles** (List). List enrollment profiles in Microsoft Intune. Returns: @odata.type, id, displayName, description, requiresUserAuthentication, configurationEndpointUrl, enableAuthenticationViaCompanyPortal, requireCompanyPortalOnSetupAssistantEnrolledDevices.
- **List all Microsoft Intune imported device identities** (List). List imported device identities registered with Microsoft Intune (devices pre-registered by IMEI, serial number, or manufacturer/model/serial before enrollment). Returns each identity's id, importedDeviceIdentifier, importedDeviceIdentityType, description, enrollmentState, platform, createdDateTime, lastModifiedDateTime, lastContactedDateTime.
- **Get single Microsoft Intune imported device identity by ID** (Get). Get a single imported device identity by id. Returns: id, importedDeviceIdentifier, importedDeviceIdentityType, description, enrollmentState, platform, createdDateTime, lastModifiedDateTime, lastContactedDateTime. Required: id.
- **Create a Microsoft Intune imported device identity** (Create). Create (pre-register) a single imported device identity in Microsoft Intune. Returns the created identity (201 Created).
- **Delete a Microsoft Intune imported device identity by ID** (Delete). Delete an imported device identity by id. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune imported device identity by ID** (Update). Update an existing imported device identity by id. Returns the updated identity (200 OK). Required: id.
- **Microsoft Intune imported device identities import device identity list** (Import). Bulk-import a list of device identities into Microsoft Intune in a single call. Returns a 200 OK with one importedDeviceIdentityResult per submitted identity, each carrying a status flag indicating whether that individual item succeeded. Required: importedDeviceIdentities.
- **Microsoft Intune imported device identities search existing identities** (Search). Check which of a submitted list of device identities already exist as imported device identities in Microsoft Intune. Returns a 200 OK with the subset of submitted identities that were found to already exist. Required: importedDeviceIdentities.
- **List all Microsoft Intune android device owner enrollment profiles** (List). List androidDeviceOwnerEnrollmentProfiles in Microsoft Intune. Returns: @odata.type, accountId, id, displayName, description, enrollmentMode, enrollmentTokenType, createdDateTime, lastModifiedDateTime, tokenValue, tokenCreationDateTime, tokenExpirationDateTime, enrolledDeviceCount, enrollmentTokenUsageCount, qrCodeContent, qrCodeImage, roleScopeTagIds, configureWifi, wifiSsid, wifiPassword,…
- **Get android device owner enrollment profile by ID** (Get). Get a single androidDeviceOwnerEnrollmentProfile by id in Microsoft Intune. Returns: @odata.type, id, displayName, value. Required: id.
- **Create a Microsoft Intune android device owner enrollment profile** (Create). Create a new androidDeviceOwnerEnrollmentProfile in Microsoft Intune. Returns the created profile including id, accountId, displayName, enrollmentMode, enrollmentTokenType, createdDateTime, lastModifiedDateTime, and Wi-Fi configuration properties.
- **Delete a Microsoft Intune android device owner enrollment profile by ID** (Delete). Delete an androidDeviceOwnerEnrollmentProfile by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune android device owner enrollment profile by ID** (Update). Update the properties of an androidDeviceOwnerEnrollmentProfile by id in Microsoft Intune. Returns the updated profile including id, accountId, displayName, enrollmentMode, enrollmentTokenType, lastModifiedDateTime, configureWifi, wifiSsid, wifiSecurityType, and deviceNameTemplate. Required: id.
- **Microsoft Intune android device owner enrollment profiles revoke token** (Revoke). Revoke the enrollment token for an Android device owner enrollment profile in Microsoft Intune. Returns an empty 204 response on success. Required: android_device_owner_enrollment_profile_id.
- **Microsoft Intune android device owner enrollment profiles create token** (Create). Create a new enrollment token for an Android device owner enrollment profile in Microsoft Intune. Returns an empty 204 response on success. Required: android_device_owner_enrollment_profile_id.
- **Device app management sync microsoft store for business apps** (Sync). Sync the Intune account with Microsoft Store for Business to trigger an application sync. Returns an empty 204 response on success.
- **List all Microsoft Intune device app management** (List). Get the Intune deviceAppManagement singleton object, which contains Microsoft Store for Business onboarding and sync configuration. Returns: @odata.type, id, isEnabledForMicrosoftStoreForBusiness, microsoftStoreForBusinessLanguage, microsoftStoreForBusinessLastCompletedApplicationSyncTime, microsoftStoreForBusinessLastSuccessfulSyncDateTime, microsoftStoreForBusinessPortalSelection.type.
- **Microsoft Intune device app management bulk update** (Update). Update properties of the Intune deviceAppManagement singleton object, including Microsoft Store for Business sync and portal selection settings. Returns: @odata.type, id, isEnabledForMicrosoftStoreForBusiness, microsoftStoreForBusinessLanguage, microsoftStoreForBusinessLastCompletedApplicationSyncTime, microsoftStoreForBusinessLastSuccessfulSyncDateTime, microsoftStoreForBusinessPortalSelection,…
- **List all Microsoft Intune mobile app troubleshooting events** (List). List mobile app troubleshooting events in Microsoft Intune. Returns: @odata.type, id, eventDateTime, correlationId, troubleshootingErrorDetails, eventName, additionalInformation, managedDeviceIdentifier, userId, applicationId, history.
- **Get single Microsoft Intune mobile app troubleshooting event by ID** (Get). Get a mobile app troubleshooting event by id in Microsoft Intune. Returns: @odata.type, id, eventDateTime, correlationId, troubleshootingErrorDetails, eventName, additionalInformation, managedDeviceIdentifier, userId, applicationId, history. Required: id.
- **Create a Microsoft Intune mobile app troubleshooting event** (Create). Create a mobile app troubleshooting event in Microsoft Intune. Returns the created event including id, eventDateTime, correlationId, applicationId, userId, and troubleshootingErrorDetails.
- **Delete a Microsoft Intune mobile app troubleshooting event by ID** (Delete). Delete a mobile app troubleshooting event by id in Microsoft Intune. Returns an empty 204 response on success. Required: id.
- **Update a Microsoft Intune mobile app troubleshooting event by ID** (Update). Update a mobile app troubleshooting event by id in Microsoft Intune. Returns the updated event including id, eventDateTime, correlationId, applicationId, userId, and troubleshootingErrorDetails. Required: id.
- **List all Microsoft Intune privilege management elevation requests** (List). List privilege management elevation requests in Microsoft Intune EPM. Returns: @odata.type, id, requestedByUserId, requestedOnDeviceId, requestedByUserPrincipalName, deviceName, requestCreatedDateTime, requestLastModifiedDateTime, requestJustification, applicationDetail, status, reviewCompletedByUserId, reviewCompletedByUserPrincipalName, reviewCompletedDateTime, requestExpiryDateTime,…
- **Get single Microsoft Intune privilege management elevation request by ID** (Get). Get a single privilege management elevation request in Microsoft Intune EPM by id. Returns: @odata.type, id, keepEnrollmentData, keepUserData, macOsUnlockCode, obliterationBehavior, persistEsimDataPlan. Required: id.
- **Microsoft Intune privilege management elevation requests approve** (Approve). Approve a pending privilege management elevation request in Microsoft Intune EPM. Returns the updated elevation request including id, status, reviewCompletedByUserId, reviewCompletedByUserPrincipalName, reviewCompletedDateTime, and reviewerJustification. Required: privilege_management_elevation_request_id.
- **Microsoft Intune privilege management elevation requests deny** (Action). Deny a pending privilege management elevation request in Microsoft Intune EPM. Returns the updated elevation request including id, status, reviewCompletedByUserId, reviewCompletedByUserPrincipalName, reviewCompletedDateTime, and reviewerJustification. Required: privilege_management_elevation_request_id.
- **Microsoft Intune privilege management elevation requests revoke** (Revoke). Revoke an approved privilege management elevation request in Microsoft Intune EPM. Returns the updated elevation request including id, status, reviewCompletedByUserId, reviewCompletedByUserPrincipalName, reviewCompletedDateTime, and reviewerJustification. Required: privilege_management_elevation_request_id.
- **List all Microsoft Intune me** (List). Get the current authenticated user's profile in Microsoft Intune via the Microsoft Graph /me endpoint. Returns: id, value.
- **List all Microsoft Intune mobile app install summary** (List). Get the install status summary for a Microsoft Intune mobile app across all assigned devices and users: counts of installed, failed, not applicable, not installed, and pending-install, broken out by device and by user. Required: mobile_app_id.
- **List all Microsoft Intune groups** (List). List Microsoft Entra ID (Azure AD) groups in the tenant — Microsoft 365 groups, security groups, and distribution groups. Returns each group's core attributes by default: id, displayName, description, mail, mailEnabled, mailNickname, groupTypes, securityEnabled, visibility, createdDateTime, expirationDateTime, and more. Additional properties are available via $select.
- **Get single Microsoft Intune group by ID** (Get). Get a single Microsoft Entra ID group by id. Returns the default property set unless $select is used. Required: id.
- **Create a Microsoft Intune group** (Create). Create a new Microsoft Entra ID group — a Microsoft 365 group, security group, or dynamic group depending on the properties supplied. Returns the created group's default properties (201 Created). Required: displayName, mailEnabled, mailNickname, securityEnabled.
- **Update a Microsoft Intune group by ID** (Update). Update a Microsoft Entra ID group's properties. Supply only the fields that should change. Returns an empty 204 response on success in most cases (200 OK with a small set of specific properties, e.g. hideFromAddressLists). Required: id.
- **Delete a Microsoft Intune group by ID** (Delete). Delete a Microsoft Entra ID group. Returns an empty 204 response on success. Required: id.
- **List all Microsoft Intune users** (List). List Microsoft Entra ID (Azure AD) user accounts in the tenant. By default only a limited property set is returned: businessPhones, displayName, givenName, id, jobTitle, mail, mobilePhone, officeLocation, preferredLanguage, surname, userPrincipalName. Request additional properties via $select.
- **Get single Microsoft Intune user by ID** (Get). Get a single Microsoft Entra ID user by id or userPrincipalName. Returns the default property set unless $select is used. Required: id.
- **Create a Microsoft Intune user** (Create). Create a new Microsoft Entra ID user. Returns the created user (201 Created). Required: accountEnabled, displayName, mailNickname, userPrincipalName, passwordProfile.
- **Update a Microsoft Intune user by ID** (Update). Update a Microsoft Entra ID user's properties. Supply only the fields that should change. Returns an empty 204 response on success. Required: id.
- **Delete a Microsoft Intune user by ID** (Delete). Delete a Microsoft Entra ID user. Returns an empty 204 response on success. Required: id.
- **List all Microsoft Intune organization** (List). Get the calling tenant's organization profile from Microsoft Entra ID. Always returns a single-item collection — the tenant has exactly one organization object. Returns: id (tenant id), displayName, businessPhones, city, country, countryLetterCode, createdDateTime, defaultUsageLocation, preferredLanguage, tenantType, technicalNotificationMails, directorySizeQuota, and more.
- **Get single Microsoft Intune organization by ID** (Get). Get the tenant's organization object by id. Since a tenant has exactly one organization object, this returns the same data as the list method scoped by id. Returns: id, displayName, businessPhones, city, country, tenantType, directorySizeQuota, and more. Required: id (the tenant/organization id).
- **Update a Microsoft Intune organization by ID** (Update). Update the tenant's organization properties. Only a small subset of properties are writable — most organization fields are directory-managed and read-only. Returns an empty 204 response on success. Required: id.
- **List all Microsoft Intune role definitions** (List). List Microsoft Intune role-based access control (RBAC) role definitions — the built-in and custom roles that determine what actions an Intune administrator can perform. Returns each definition's id, displayName, description, rolePermissions (allowed and not-allowed resource actions), and isBuiltIn.
- **List all Microsoft Intune role assignments** (List). List the role assignments for a Microsoft Intune RBAC role definition — the groups and scopes that a given role has been assigned to. Returns each assignment's id, displayName, description, and resourceScopes (the Entra ID group ids the assignment's scope is limited to). Required: role_definition_id.
- **List all Microsoft Intune resource operations** (List). List the resource operations available in Microsoft Intune — the individual permission strings (e.g. Microsoft.Intune/MobileApps/Read) that can be granted or denied within a role definition's rolePermissions. Use this to discover valid values when constructing a custom role definition.
- **List all Microsoft Intune managed device users** (List). List the primary user(s) assigned to a Microsoft Intune managed device, with pagination. This is the Primary user shown in the Intune admin center and reflects reassignments made by an admin, unlike the userId/userPrincipalName/userDisplayName fields on the managed device object, which represent the enrolled-by user and do not change after enrollment. Returns: @odata.type, id. Only the user id is returned by Microsoft Graph; resolve the user's name and email via the users resource (get with the returned id). Required: managed_device_id.
- **List all Microsoft Intune managed devices beta** (List). List managed devices enrolled in Microsoft Intune using the Graph beta endpoint. Unlike the v1.0 managed_devices resource, this returns deviceType (desktop, iPhone, iPad, macMDM, cloudPC, ...) and chassisType. chassisType and hardwareInformation come back as 'unknown'/defaults on this list call by design; use managed_devices_beta get with $select to read the actual chassis type. Supports $filter, $select, $orderby, $expand and $count. Paginated. Returns: @odata.type, id, userId, deviceName, hardwareInformation, ownerType, managedDeviceOwnerType, managementState, enrolledDateTime, lastSyncDateTime, chassisType, operatingSystem, deviceType, complianceState, jailBroken, managementAgent, osVersion, azureADRegistered, deviceEnrollmentType, lostModeState, emailAddress, azureADDeviceId, deviceRegistrationState, deviceCategoryDisplayName, isSupervised, isEncrypted, userPrincipalName, model, manufacturer, imei, serialNumber, phoneNumber, androidSecurityPatchLevel, userDisplayName, wiFiMacAddress, ethernetMacAddress, totalStorageSpaceInBytes, freeStorageSpaceInBytes, physicalMemoryInBytes, managedDeviceName, partnerReportedThreatState, autopilotEnrolled, joinType, processorArchitecture, skuFamily, enrollmentProfileName, notes, udid, iccid.
- **Get single Microsoft Intune managed devices beta by ID** (Get). Get a single Intune managed device by id using the Graph beta endpoint. Pass $select to retrieve non-default hardware inventory properties such as chassisType (desktop, laptop, worksWorkstation, enterpriseServer, phone, tablet, ...), hardwareInformation, ethernetMacAddress and physicalMemoryInBytes, which are only populated on this single-device GET. Returns: @odata.type, id, userId, deviceName, hardwareInformation, ownerType, managedDeviceOwnerType, managementState, enrolledDateTime, lastSyncDateTime, chassisType, operatingSystem, deviceType, complianceState, jailBroken, managementAgent, osVersion, azureADRegistered, deviceEnrollmentType, lostModeState, emailAddress, azureADDeviceId, deviceRegistrationState, deviceCategoryDisplayName, isSupervised, isEncrypted, userPrincipalName, model, manufacturer, imei, serialNumber, phoneNumber, androidSecurityPatchLevel, userDisplayName, wiFiMacAddress, ethernetMacAddress, totalStorageSpaceInBytes, freeStorageSpaceInBytes, physicalMemoryInBytes, managedDeviceName, partnerReportedThreatState, autopilotEnrolled, joinType, processorArchitecture, skuFamily, enrollmentProfileName, notes, udid, iccid.
