Overview
The Microsoft Intune integration monitors your managed device fleet: compliance status, encryption (BitLocker/FileVault), OS versions, and security configurations across Windows, macOS, iOS, and Android. LowerPlane uses read-only OAuth 2.0 permissions via Microsoft Graph API.Prerequisites
Required Permissions
| Permission | Purpose |
|---|---|
DeviceManagementManagedDevices.Read.All | Read managed device details and compliance |
DeviceManagementConfiguration.Read.All | Read device configuration profiles |
DeviceManagementApps.Read.All | Read managed app information |
Device.Read.All | Read device properties |
How to Connect
Navigate to Integrations
Go to Integrations from the main navigation and search for Microsoft Intune.
Authorize
You will be redirected to the Microsoft login page. Sign in with your admin credentials and click Accept to grant read-only device management permissions.
What LowerPlane Monitors
Managed Devices
Full inventory of enrolled devices with OS, model, and enrollment status.
Compliance Status
Device compliance against configured policies (encryption, passcode, OS version).
Encryption
BitLocker (Windows) and FileVault (macOS) encryption status per device.
Configuration Profiles
Applied device configuration profiles and their compliance state.
Intune data is used to evaluate device security tests automatically — such as “All devices have disk encryption enabled” and “All devices run a supported OS version.”
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Endpoint security controls and device management |
| ISO 27001 | A.8.1 User endpoint devices, A.8.9 Configuration management |
| HIPAA | §164.310(c) Workstation security, §164.312(a) Access controls |
| PCI-DSS | Req 5 Malware protection on endpoints |