Key information about the managed devices such as device security and compliance information, operating system and network details, enrolment information, and usage metrics are synced with Oomnitza.
You can also create workflows to complete actions in Microsoft Intune such as
-
Managing device security
- Remote locking
- Resetting a device PassCode, shutting down, and locking a device.
- Offboarding and onboarding a device, including cleaning, wiping, deleting, retiring, and rebooting a device.
- Managing a device such as including updating and recovering a PassCode.
Navigation
Creating the asset integration
Before you start
To easily find the records that are uploaded to Oomnitza, it's best practice to create a dedicated user account for each integration. This will make it easier for you to retrieve the records that are uploaded to Oomnitza from the vendor application.
When you add the integration, you can choose to retrieve all records or filter the records that are retrieved by specifying a value since the last time the data was synced..
Adding credentials
Complete the following actions:
-
Generating your OAuth2.0 credentials in Azure. The Microsoft Intune Asset Load uses the Microsoft Graph List managed devices API and requires the following permissions to be set when you generate your credentials:
DeviceManagementManagedDevices.Read.All-
DeviceManagementManagedDevices.ReadWrite.All
-
Adding your Microsoft credentials in Oomnitza. The following information is required
- Client ID, secret, and token ID. See Adding your Microsoft credentials in Oomnitza.
- Scope. The value for the scope is
https://graph.microsoft.com/.default.
Dos and don'ts
To authorize Oomnitza with Microsoft Intune, use a dedicated Microsoft Intune account such as a delegated service account or admin account. See Delegated access. Alternatively, create an account with global administrator permissions, or application administrator permissions, or an app user account with
DeviceManagementManagedDevices.Read.Allpermissions.
To authorize Oomnitza with Microsoft Intune, don't use a Microsoft Intune account that requires admin approval, or an account with temporarily elevated permissions because the token will not refresh with the same permissions when Oomnitza subsequently syncs with the Microsoft Intune tenant.
Note
The Microsoft Graph API for Intune requires an active Intune license for the tenant.
Creating the asset integration
- In Oomnitza, click Configuration> Integrations> Overview.
- Click Block view
- Scroll down to the Extended section for asset integrations.
- Click NEW INTEGRATION.
- Select the integration in the sidebar.
- Click ADD.
Integration details overview
More information is provided about the following fields to help you complete the integration:
Software data
Depending on the asset integration, an option might be available to ingest desktop software information such as the name and version of the software installed on an asset. To view the software information in Oomnitza, you must have the software module.
Installation types
- Cloud. Store credentials in the Oomnitza cloud.
- Local. Store credentials locally. If you want to sync Oomnitza with vendor applications that require AWS or OAUTH authentication, select cloud as the type of installation. Local installations don't support AWS and OAuth authentication.
Integration preferences
- Create & Update. Add and update records.
- Create only. Add records.
- Update only. Update records.
Integration details
To review or update the integrations details, click Edit .
When you edit the Integration details section, you can select the name or names of integration contacts. Integration contacts will receive an in-app notification and an email, when the integration fails, when the integration fails to complete within 24 hours, or when the scheduled integration fails to run.
- Update the integration name.
- Select an installation type.
- For integration preferences, select an option.
- Enter the name of the integration user.
Credential details
If you selected Cloud as the installation type, choose one of the following options:
- Select the credentials that were created for the integration.
- Edit the credentials that were created for the integration.
- Create new credentials
Scheduling the integration
By default, data is synced once every day. Change the interval or the time so that the data is streamed when your system isn't busy.
- Click Edit
.
- Make and save your changes.
Mapping fields to Oomnitza
To map the fields to Oomnitza, click Edit .
Select Edit integration to add rules for syncing data.
Filtering integration results.
Click SMART MAPPING.
You can add new fields to your integration by selecting Add new field on the mapping page.
Creating custom API fields.
Creating custom mappings
Map the Intune fields to the Oomnitza fields and create custom mappings to get the information that you need to manage your desktop assets.
- Click Smart Mapping to automatically detect appropriate mapping fields. Values from the integration can also be dragged to the appropriate field on the Oomnitza side, or selected from the integration field dropdown.
- Create a custom mapping for the Microsoft Intune Device ID. Complete the following steps:
- Click the down arrow on the ID.
- Select Add new Oomnitza assets field.
- Change the name of the field to Microsoft Intune Device ID.
- Click CREATE.
- Map and assign a sync key to a unique field, such as the Serial Number.
Standard mappings
You can map the following fields from Intune to Oomnitza:
Activation Lock Bypass Code
Android Security Patch Level
AzureAD Device ID
Compliance Grace Period Expiration DateTime
Compliance State
Configuration Manager Client Enabled Features
Device Category Display Name
Device Enrollment Type
Device Health Attestation State
Device Name
Device Registration State
EAS Activated
EAS Activation DateTime
EAS Device ID
Email of the associated user
Enrolled DateTime
Exchange Access State
Exchange Access State Reason
Exchange Last Successful Sync DateTime
Free Storage In Bytes
ID
IMEI
Is Encrypted
Is Supervised
Is registered in Azure AD
Jail Broken
Last sync date and time with Intune
MEID
Managed Device Name
Managed Device Owner Type
Management Agent
Manufacturer
Model
OS
OS version
Partner Reported Threat State
Phone Number
Remote Assistance Session Error Details
Remote Assistance Session Url
Serial Number
Subscriber Carrier
Total Storage In Bytes
User Display Name
User ID
User Principal Name
Wi-Fi MAC
Launching the integration
Your integration is in Draft mode until the required mandatory fields are added. When added, click Launch to activate your integration.
If you selected Cloud as the installation type when creating the integration, see Running an extended integration
If you selected Local as the installation type when creating the integration, see Running an extended integration locally.
Viewing data ingested by Oomnitza
Viewing ingested asset data
For asset integrations, click Hardware. If the asset integration also ingests software data, click Software.
Viewing ingested user data
For user integrations, click People. If you chose the option to ingest User and SaaS user data, click Software > SaaS, click the SaaS app, and then click the Users tab.
Related Links
Comments
0 comments
Please sign in to leave a comment.