Microsoft Intune

Microsoft Intune helps organizations manage devices, applications, and compliance policies.

With the Microsoft Intune block, you can:

  • Review device inventory: Read managed devices, their owners, operating systems, and compliance states.
  • Inspect installed apps: List detected applications and the devices where they were found.
  • Review policies: Read compliance and configuration metadata, and inspect compliance policy device statuses.
  • Request device actions: Sync, restart, remotely lock, or retire a selected device. Restart, lock, and retirement require explicit confirmation.

Connect a Microsoft work or school account with an appropriate Intune role. The tenant needs an active Intune license and administrator consent for the delegated permissions below. Self-hosted deployments use MICROSOFT_CLIENT_ID and MICROSOFT_CLIENT_SECRET with a matching callback at /api/auth/oauth2/callback/microsoft-intune.

List operations return one page at a time. Pass nextLink to the same operation and resource to continue. Policy and configuration outputs contain common metadata; platform-specific settings are excluded. An accepted device action means Intune received the request, not that the device completed it.

In Sim, the Microsoft Intune block lets your agents prepare compliance reports, review software inventory, and coordinate approved help desk actions.

Usage Instructions

Read managed device and detected application inventories, inspect compliance policy status and device configuration metadata, and request device sync, restart, remote lock, or retirement. Uses Microsoft Graph v1.0 with a work or school account and an active Intune tenant license. Remote actions depend on device platform and the connected administrator’s Intune permissions.

Actions

Microsoft Intune List Devices

Read one page of devices from Microsoft Intune

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource
filterstringNoOData filter, for example complianceState eq 'noncompliant'; ignored with nextLink

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
devicesarrayList Devices
↳ idstringIntune managed device ID
↳ deviceNamestringDevice name
↳ managedDeviceOwnerTypestringOwnership: company, personal, or unknown
↳ managementStatestringCurrent device management state
↳ enrolledDateTimestringEnrollment time
↳ lastSyncDateTimestringLast check-in time
↳ operatingSystemstringOperating system
↳ osVersionstringOperating system version
↳ complianceStatestringDevice compliance state
↳ isEncryptedbooleanWhether device storage is encrypted
↳ userIdstringPrimary user ID
↳ userPrincipalNamestringPrimary user principal name
↳ userDisplayNamestringPrimary user display name
↳ emailAddressstringUser email address
↳ azureADDeviceIdstringMicrosoft Entra device ID
↳ serialNumberstringDevice serial number
↳ manufacturerstringDevice manufacturer
↳ modelstringDevice model
↳ totalStorageSpaceInBytesnumberTotal storage capacity in bytes
↳ freeStorageSpaceInBytesnumberAvailable storage in bytes

Microsoft Intune Get Device

Read device details from Microsoft Intune

Input

ParameterTypeRequiredDescription
managedDeviceIdstringYesIntune managed device ID (not the Microsoft Entra device ID)

Output

ParameterTypeDescription
devicejsonGet Device
↳ idstringIntune managed device ID
↳ deviceNamestringDevice name
↳ managedDeviceOwnerTypestringOwnership: company, personal, or unknown
↳ managementStatestringCurrent device management state
↳ enrolledDateTimestringEnrollment time
↳ lastSyncDateTimestringLast check-in time
↳ operatingSystemstringOperating system
↳ osVersionstringOperating system version
↳ complianceStatestringDevice compliance state
↳ isEncryptedbooleanWhether device storage is encrypted
↳ userIdstringPrimary user ID
↳ userPrincipalNamestringPrimary user principal name
↳ userDisplayNamestringPrimary user display name
↳ emailAddressstringUser email address
↳ azureADDeviceIdstringMicrosoft Entra device ID
↳ serialNumberstringDevice serial number
↳ manufacturerstringDevice manufacturer
↳ modelstringDevice model
↳ totalStorageSpaceInBytesnumberTotal storage capacity in bytes
↳ freeStorageSpaceInBytesnumberAvailable storage in bytes

Microsoft Intune List Detected Apps

Read one page of detected apps from Microsoft Intune

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
appsarrayList Detected Apps
↳ idstringDetected application ID
↳ displayNamestringApplication display name
↳ versionstringApplication version
↳ sizeInBytenumberApplication size in bytes
↳ deviceCountnumberNumber of devices with this application
↳ publisherstringApplication publisher
↳ platformstringApplication platform

Microsoft Intune Get Detected App

Read detected app details from Microsoft Intune

Input

ParameterTypeRequiredDescription
detectedAppIdstringYesDetected application ID

Output

ParameterTypeDescription
appjsonGet Detected App
↳ idstringDetected application ID
↳ displayNamestringApplication display name
↳ versionstringApplication version
↳ sizeInBytenumberApplication size in bytes
↳ deviceCountnumberNumber of devices with this application
↳ publisherstringApplication publisher
↳ platformstringApplication platform

Microsoft Intune List App Devices

Read one page of managed devices that have a detected application installed

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource
detectedAppIdstringYesDetected application ID

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
devicesarrayList App Devices
↳ idstringIntune managed device ID
↳ deviceNamestringDevice name
↳ managedDeviceOwnerTypestringOwnership: company, personal, or unknown
↳ managementStatestringCurrent device management state
↳ enrolledDateTimestringEnrollment time
↳ lastSyncDateTimestringLast check-in time
↳ operatingSystemstringOperating system
↳ osVersionstringOperating system version
↳ complianceStatestringDevice compliance state
↳ isEncryptedbooleanWhether device storage is encrypted
↳ userIdstringPrimary user ID
↳ userPrincipalNamestringPrimary user principal name
↳ userDisplayNamestringPrimary user display name
↳ emailAddressstringUser email address
↳ azureADDeviceIdstringMicrosoft Entra device ID
↳ serialNumberstringDevice serial number
↳ manufacturerstringDevice manufacturer
↳ modelstringDevice model
↳ totalStorageSpaceInBytesnumberTotal storage capacity in bytes
↳ freeStorageSpaceInBytesnumberAvailable storage in bytes

Microsoft Intune List Compliance Policies

Read one page of compliance policies from Microsoft Intune

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
policiesarrayList Compliance Policies
↳ idstringPolicy or configuration ID
↳ displayNamestringPolicy or configuration name
↳ descriptionstringAdministrator-provided description
↳ createdDateTimestringCreation time
↳ lastModifiedDateTimestringLast modification time
↳ versionnumberPolicy or configuration version

Microsoft Intune Get Compliance Policy

Read common metadata for an Intune compliance policy

Input

ParameterTypeRequiredDescription
compliancePolicyIdstringYesDevice compliance policy ID

Output

ParameterTypeDescription
policyjsonGet Compliance Policy
↳ idstringPolicy or configuration ID
↳ displayNamestringPolicy or configuration name
↳ descriptionstringAdministrator-provided description
↳ createdDateTimestringCreation time
↳ lastModifiedDateTimestringLast modification time
↳ versionnumberPolicy or configuration version

Microsoft Intune List Compliance Policy Device Statuses

Read one page of compliance policy device statuses from Microsoft Intune

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource
compliancePolicyIdstringYesDevice compliance policy ID

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
deviceStatusesarrayList Compliance Policy Device Statuses
↳ idstringDevice status record ID
↳ deviceDisplayNamestringDevice display name
↳ userNamestringUser name
↳ deviceModelstringDevice model
↳ statusstringReported compliance status
↳ lastReportedDateTimestringLast status report time
↳ userPrincipalNamestringUser principal name
↳ complianceGracePeriodExpirationDateTimestringCompliance grace period expiration

Microsoft Intune List Device Configurations

Read one page of device configurations from Microsoft Intune

Input

ParameterTypeRequiredDescription
topnumberNoRequested page size from 1 to 1000 (default: 100); ignored with nextLink
nextLinkstringNoThe nextLink from the previous response for this same operation and resource

Output

ParameterTypeDescription
nextLinkstringContinuation URL for the next page; null when this is the final page
configurationsarrayList Device Configurations
↳ idstringPolicy or configuration ID
↳ displayNamestringPolicy or configuration name
↳ descriptionstringAdministrator-provided description
↳ createdDateTimestringCreation time
↳ lastModifiedDateTimestringLast modification time
↳ versionnumberPolicy or configuration version

Microsoft Intune Get Device Configuration

Read common metadata for an Intune device configuration

Input

ParameterTypeRequiredDescription
configurationIdstringYesDevice configuration ID

Output

ParameterTypeDescription
configurationjsonGet Device Configuration
↳ idstringPolicy or configuration ID
↳ displayNamestringPolicy or configuration name
↳ descriptionstringAdministrator-provided description
↳ createdDateTimestringCreation time
↳ lastModifiedDateTimestringLast modification time
↳ versionnumberPolicy or configuration version

Microsoft Intune Sync Device

Request a device check-in to receive pending Intune policies and actions

Input

ParameterTypeRequiredDescription
managedDeviceIdstringYesIntune managed device ID (not the Microsoft Entra device ID)

Output

ParameterTypeDescription
acceptedbooleanMicrosoft Intune accepted the request; device completion is asynchronous

Microsoft Intune Reboot Device

Request a device restart after explicit confirmation; may interrupt the signed-in user

Input

ParameterTypeRequiredDescription
managedDeviceIdstringYesIntune managed device ID (not the Microsoft Entra device ID)
confirmActionbooleanYesExplicit user confirmation to perform this disruptive device action

Output

ParameterTypeDescription
acceptedbooleanMicrosoft Intune accepted the request; device completion is asynchronous

Microsoft Intune Remote Lock Device

Request a remote device lock after explicit confirmation on supported platforms

Input

ParameterTypeRequiredDescription
managedDeviceIdstringYesIntune managed device ID (not the Microsoft Entra device ID)
confirmActionbooleanYesExplicit user confirmation to perform this disruptive device action

Output

ParameterTypeDescription
acceptedbooleanMicrosoft Intune accepted the request; device completion is asynchronous

Microsoft Intune Retire Device

Retire a device after explicit confirmation, removing company data and management

Input

ParameterTypeRequiredDescription
managedDeviceIdstringYesIntune managed device ID (not the Microsoft Entra device ID)
confirmActionbooleanYesExplicit user confirmation to perform this disruptive device action

Output

ParameterTypeDescription
acceptedbooleanMicrosoft Intune accepted the request; device completion is asynchronous

OAuth Scopes

Sim requests these scopes when someone connects a Microsoft Intune account. On a self-hosted deployment, register your own app with the provider using the settings below. See Integrations & OAuth for the full setup.

SettingValue
Redirect URI<NEXT_PUBLIC_APP_URL>/api/auth/oauth2/callback/microsoft-intune
Environment variablesMICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET
ScopeDescription
openidStandard authentication
profileAccess profile information
emailAccess email address
DeviceManagementManagedDevices.Read.AllView Intune managed devices and detected apps
DeviceManagementConfiguration.Read.AllView Intune compliance policies, device configurations, and their device statuses
DeviceManagementManagedDevices.PrivilegedOperations.AllPerform remote Intune device actions, including syncing, rebooting, locking, and retiring devices
offline_accessAccess account when not using the application