You are here:
Create a Discovery Target for Microsoft Intune
Create a Microsoft Intune discovery target to bring managed device data into CMDB and keep endpoint configuration items (CIs) accurate and up to date. Map Intune device attributes, validate the integration connection, and run discovery using Salesforce Flow. Populate CMDB with managed computer and mobile device data, and support IT operations that rely on accurate CI data.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service that have Discovery enabled. |
| User Permissions Needed | |
|---|---|
| To manage discovery: | IT Service Asset Discovery |
| To create and manage the Intune connection: | Manage Integration Connections |
| To create and activate the integration flow: | Manage Flow |
| To use the integration template as a non-admin user: | App Framework Manage Template |
| To keep connector usage unmetered: | Unmetered Base AI Usage for Service Desk permission set |
Complete these steps before you create the target.
- Turn on Intune discovery in Salesforce Go. For more information, see Set Up Discovery using Salesforce Go.
- Make sure that the FlowIntegrationAddOn license is enabled for your org. Intune discovery runs on Salesforce Flow.
- Create an app registration in Microsoft Entra ID.
Register an application in Microsoft Entra ID to get the OAuth details for the Intune connection. During registration, complete these steps:
- Capture the Application (client) ID.
- Create a client secret and capture its Value.
- Note the Directory (tenant) ID.
- Under API permissions, add these Microsoft Graph application permissions:
DeviceManagementManagedDevices.Read.AllDeviceManagementApps.Read.AllUser.Read.All
- Grant admin consent for the permissions.
For more information, see Register an application in Microsoft Entra ID.
- From the App Launcher, find and select CMDB and Service Graph.
- From the navigation panel, select Discovery & Scanning, and then select Targets.
- Select New.
- In Target Categories, select MDM & Device Management.
- In Probe Types, select Microsoft Intune, and then select Save and Continue.
- Enter a target name.
- Optionally, enter a description and location.
-
Configure the Intune connection.
- In Intune Connection, select New Connection.
- Enter a name and description.
-
Enter the authentication details from your Microsoft Entra ID app registration.
Field Value Client ID Application (client) ID Client Secret Client secret value URL https://graph.microsoft.com/v1.0Scope https://graph.microsoft.com/.defaultToken URL https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token -
Replace
{tenant-id}with your Directory (tenant) ID. -
Save the connection.
The connections that you create appear in the Intune Connection field.
- Test the connection to confirm that Salesforce can authenticate with Microsoft Intune.
-
Turn on Software Sync to discover installed software from Intune-managed devices.
Turn off Software Sync to limit discovery to device and hardware data.
-
In Device Types to Sync, select the ownership types to include for
each device category.
Device type selection controls which Intune-managed endpoints Salesforce imports into CMDB. Use this option to align discovery with your organizational policies.
Option Description Corporate-owned Syncs only company-owned devices in that category. Employee-owned Syncs only personally owned devices. Use this option for bring-your-own-device (BYOD) policies. Both Syncs corporate-owned and employee-owned devices. None Excludes that device category from discovery. -
In Scan Frequency, select one of these options:
Option Description Immediate Runs discovery as soon as you create the target. Daily Keeps device and software data refreshed every day based on the schedule that you set. Weekly Syncs data every week based on the schedule and days that you set. - Select Next.
-
Map Intune fields to CMDB fields for compute devices, mobile devices, and installed
software. Mapping makes sure that incoming Intune data aligns with your CMDB data model and
identification rules.
- On the Field Mapping page, review how the Salesforce attributes map to the Intune device attributes for each CI type.
-
Map any unmapped Intune fields to the appropriate CMDB fields.
To capture an attribute that isn't mapped by default, create a custom field in CMDB and map the Intune attribute to it. For more information, see Considerations for Mapping Intune Fields to CMDB.
-
On the Integration Flows page, review the linked Salesforce flow for Intune
discovery.
If a flow doesn't load, retry or resolve the issue before continuing.
- Select Create and Run Flow.
CMDB creates or updates configuration items based on your field mappings and identification rules.
Select View Scan Result to open the Scan Jobs page and monitor progress. CMDB creates a dedicated scan job for each target. Each scan job shows a summary of resources by type and a detailed list of new and updated CIs.
