Overview

The Microsoft Intune integration monitors your managed device fleet: compliance status, encryption (BitLocker/FileVault), OS versions, and security configurations across Windows, macOS, iOS, and Android. LowerPlane uses read-only OAuth 2.0 permissions via Microsoft Graph API.

Prerequisites

You need Intune Administrator or Global Administrator access on your Microsoft 365 tenant.

Required Permissions

PermissionPurpose
DeviceManagementManagedDevices.Read.AllRead managed device details and compliance
DeviceManagementConfiguration.Read.AllRead device configuration profiles
DeviceManagementApps.Read.AllRead managed app information
Device.Read.AllRead device properties

How to Connect

1

Navigate to Integrations

Go to Integrations from the main navigation and search for Microsoft Intune.
2

Click Connect

Click Connect to initiate the OAuth authorization flow.
3

Authorize

You will be redirected to the Microsoft login page. Sign in with your admin credentials and click Accept to grant read-only device management permissions.
4

Confirm

Once authorized, you will be redirected back to LowerPlane. Device data begins syncing automatically.

What LowerPlane Monitors

Managed Devices

Full inventory of enrolled devices with OS, model, and enrollment status.

Compliance Status

Device compliance against configured policies (encryption, passcode, OS version).

Encryption

BitLocker (Windows) and FileVault (macOS) encryption status per device.

Configuration Profiles

Applied device configuration profiles and their compliance state.
Intune data is used to evaluate device security tests automatically — such as “All devices have disk encryption enabled” and “All devices run a supported OS version.”

Frameworks Supported

FrameworkWhat It Proves
SOC 2Endpoint security controls and device management
ISO 27001A.8.1 User endpoint devices, A.8.9 Configuration management
HIPAA§164.310(c) Workstation security, §164.312(a) Access controls
PCI-DSSReq 5 Malware protection on endpoints