Loading
Prepare for Email to Become the Default Login ExperienceRead More
Create a Discovery Target for Microsoft Intune

Create a Discovery Target for Microsoft Intune

Create a Microsoft Intune discovery target to bring managed device data into CMDB and keep endpoint configuration items (CIs) accurate and up to date. Map Intune device attributes, validate the integration connection, and run discovery using Salesforce Flow. Populate CMDB with managed computer and mobile device data, and support IT operations that rely on accurate CI data.

Required Editions

Available in: Lightning Experience
Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service that have Discovery enabled.
User Permissions Needed
To manage discovery: IT Service Asset Discovery
To create and manage the Intune connection: Manage Integration Connections
To create and activate the integration flow: Manage Flow
To use the integration template as a non-admin user: App Framework Manage Template
To keep connector usage unmetered: Unmetered Base AI Usage for Service Desk permission set
Important
Important CMDB integrations are powered by MuleSoft flow connectors, which consume automation credits. Before you create a discovery target, assign the Unmetered Base AI Usage for Service Desk permission set to each user who creates or manages discovery targets. The permission set keeps the connector usage unmetered so that it doesn't count toward your credit consumption.

Complete these steps before you create the target.

  • Turn on Intune discovery in Salesforce Go. For more information, see Set Up Discovery using Salesforce Go.
  • Make sure that the FlowIntegrationAddOn license is enabled for your org. Intune discovery runs on Salesforce Flow.
  • Create an app registration in Microsoft Entra ID.

Register an application in Microsoft Entra ID to get the OAuth details for the Intune connection. During registration, complete these steps:

  • Capture the Application (client) ID.
  • Create a client secret and capture its Value.
  • Note the Directory (tenant) ID.
  • Under API permissions, add these Microsoft Graph application permissions:
    • DeviceManagementManagedDevices.Read.All
    • DeviceManagementApps.Read.All
    • User.Read.All
  • Grant admin consent for the permissions.

For more information, see Register an application in Microsoft Entra ID.

  1. From the App Launcher, find and select CMDB and Service Graph.
  2. From the navigation panel, select Discovery & Scanning, and then select Targets.
  3. Select New.
  4. In Target Categories, select MDM & Device Management.
  5. In Probe Types, select Microsoft Intune, and then select Save and Continue.
  6. Enter a target name.
  7. Optionally, enter a description and location.
  8. Configure the Intune connection.
    1. In Intune Connection, select New Connection.
    2. Enter a name and description.
    3. Enter the authentication details from your Microsoft Entra ID app registration.
      Field Value
      Client ID Application (client) ID
      Client Secret Client secret value
      URL https://graph.microsoft.com/v1.0
      Scope https://graph.microsoft.com/.default
      Token URL https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token
    4. Replace {tenant-id} with your Directory (tenant) ID.
    5. Save the connection.
      The connections that you create appear in the Intune Connection field.
    6. Test the connection to confirm that Salesforce can authenticate with Microsoft Intune.
  9. Turn on Software Sync to discover installed software from Intune-managed devices.
    Turn off Software Sync to limit discovery to device and hardware data.
  10. In Device Types to Sync, select the ownership types to include for each device category.

    Device type selection controls which Intune-managed endpoints Salesforce imports into CMDB. Use this option to align discovery with your organizational policies.

    Option Description
    Corporate-owned Syncs only company-owned devices in that category.
    Employee-owned Syncs only personally owned devices. Use this option for bring-your-own-device (BYOD) policies.
    Both Syncs corporate-owned and employee-owned devices.
    None Excludes that device category from discovery.
  11. In Scan Frequency, select one of these options:
    Option Description
    Immediate Runs discovery as soon as you create the target.
    Daily Keeps device and software data refreshed every day based on the schedule that you set.
    Weekly Syncs data every week based on the schedule and days that you set.
  12. Select Next.
  13. Map Intune fields to CMDB fields for compute devices, mobile devices, and installed software. Mapping makes sure that incoming Intune data aligns with your CMDB data model and identification rules.
    1. On the Field Mapping page, review how the Salesforce attributes map to the Intune device attributes for each CI type.
    2. Map any unmapped Intune fields to the appropriate CMDB fields.
      To capture an attribute that isn't mapped by default, create a custom field in CMDB and map the Intune attribute to it. For more information, see Considerations for Mapping Intune Fields to CMDB.
  14. On the Integration Flows page, review the linked Salesforce flow for Intune discovery.
    If a flow doesn't load, retry or resolve the issue before continuing.
  15. Select Create and Run Flow.

CMDB creates or updates configuration items based on your field mappings and identification rules.

Select View Scan Result to open the Scan Jobs page and monitor progress. CMDB creates a dedicated scan job for each target. Each scan job shows a summary of resources by type and a detailed list of new and updated CIs.

 
Loading
Salesforce Help | Article