 # Microsoft Intune

```{info}
Mobile Device Management (MDM) is a solution that is used to remotely manage devices mobile devices. It is most commonly used in large enterprises to manage the mobile devices of mobile devices of employees in order to maintain an appropriate degree of security.
The MDM solution provides for integration with external systems such as NACVIEW.
The collaboration of the two solutions serves to share data so as to secure both the devices mobile devices, as well as the network on which they reside.
```

1. Log on to https://portal.azure.com

```{thumbnail} /_images/configuration-guides/intune-mdm/1.png
:alt: 1.png
:width: 50 %
```

2. From the **Azure services** section, select **App registrations**.

```{thumbnail} /_images/configuration-guides/intune-mdm/2.png
:alt: 2.png
:width: 50 %
```

3. Click the **New registration** button.
4. Fill in the **Name** field with any name and click **Register**. The following window should appear:

```{thumbnail} /_images/configuration-guides/intune-mdm/3.png
:alt: 3.png
:width: 50 %
```

5. Without closing the window, go to the NACVIEW system and select **Integration servers** from the main menu (Configuration section).

```{thumbnail} /_images/configuration-guides/intune-mdm/4.png
:alt: 4.png
:width: 50 %
```

6. Edit the line with Microsoft Intune.

```{thumbnail} /_images/configuration-guides/intune-mdm/5.png
:alt: 5.png
:width: 50 %
```

7. Go back to the Microsoft Azure window, copy the **Application (client) ID** parameter and paste it in NACVIEW in the field **Username / login**.
8. Repeat with the **Directory (tenant) ID** parameter, pasting it in NACVIEW into the **Tenant** field.
9. Go to Microsoft Azure again and from the menu on the left, select **API permissions**, then click **Add a permission**.
10. In the window that appears on the right, select **Microsoft Graph** and then **Application permissions**.
11. in the list that appears, locate **Device** and check the **DeviceManagementManagedDevices.Read.All** and **User.Read.All** checkbox.

```{thumbnail} /_images/configuration-guides/intune-mdm/nacview_-_microsoft_azure.jpg
:alt: nacview_-_microsoft_azure.jpg
:width: 50 %
```

```{warning}
Note that the DeviceName must be unique in the MDM for synchronisation to work correctly.
```


12. Click the **Add permissions** button at the bottom of the window. 
13. The new permissions must be approved by the Azure Active Directory service administrator. If you are using has administrator permissions, then click **Grant admin consent for** ... and confirm with the **Yes** button.
14. Select **Certificates & secrets** from the menu on the left, and then click **New client secret**.
15. Enter any description in the **Description** field, and from the **Expires** checkbox select **Never**.

```{thumbnail} /_images/configuration-guides/intune-mdm/6-popr.png
:alt: 6-popr.png
:width: 50 %    
```

16. Confirm with **Add** button. The added parameter will appear in the table under the **New client secret** button. Copy the value from the **Value** column.

17. Go to NACVIEW. Click **Change/set password** and into the **Password / secret** field paste the previously copied **Value**.

18. Save the set values. 

