IMPLEMENTATION
Implementing the Microsoft Intune connector for Xurrent is simple and straight forward. The process itself takes a few minutes to complete and requires minimal effort to implement. There are a few requirements that must be in place, to install the app and most of these deals with access rights in Intune and Xurrent.
Intune prerequisites
To get devices into Xurrent you would need to have the required licenses for Intune for the users and or devices. Please see the following link for more details on Licenses available for Microsoft Intune | Microsoft Docs. Following this as part of the installation there will be a request for providing Azure Active Directory credentials that has enough rights to consent to giving the following rights to a Service Principal in Azure Active Directory.
- Sign in and read user profile
- Read Microsoft Intune devices
- Read Microsoft Intune policy
Xurrent Prerequisites
The following artifacts will be implemented into Xurrent as part of the connector configuration.
- CI UI Extension (Intune data attributes)
- Automation rules
To install the app in your Xurrent environment you would have to have one or more of the following roles:
- Account owner
- Account designer
- Account administrator
Installing the Microsoft Intune for Xurrent connector
The end-to-end process for installing the connector is illustrated below. The installation should take no more than 9 minutes to complete.
Create the connector
To create the connector in the QRatify portal follow these steps:
-
Create a “Xurrent – Intune Connector” resource
- Use the link that has been provided to you to go to the QRatify portal
- Click Sign In
- Complete the sign-in with the user that you want to make administrator in the QRatify Platform
- Click Products
- Click Create on the product offering called “Xurrent - Intune Connector”
-
Give the Resource a name and place it in a Subscription
-
Click Create
-
Connect the resource to Xurrent
-
Copy to code
-
Go to the App Store in Xurrent
-
Click Add on the Microsoft Intune Connector
-
Confirm the fact that the App uses a person record which is a billable user.
-
At step 2, enter the code from the QRatify Portal
-
Click Save
- Go back to the resource previously created in the QRatify Portal
-
-
Connect to Microsoft Intune
- If the Xurrent connection doesn’t show a checkmark, wait a bit an click Refresh.
-
Once the connection is established, click Next.
-
In the Tenant domain textbox, enter the name of the Intune domain you want to connect to.
-
Once the domain has been validated, click Connect
-
A new tab in the browser opens where you can review, consent and give access to the Intune domain
-
If the user you’re currently logged in with doesn’t have the required permission or is from the wrong tenant you’ll be notified and have the option to switch account or send a link to a user that has the required permissions.
-
When you have switch to an account the has the required permissions you can see information about the connection your about to make.
-
Once pleased click Consent, this will start the actual Consent process to setup the connection.
Note
You might be prompted to select Account again in this process but that is currently by design.
-
Once you have reviewed the requested permissions, terms and completed the Consent process the page will inform you that the integration was successful.
-
You can now return to the previous browser tab showing your connector resource connected to both Xurrent and Intune.
-
Once confirmed that the connection is established click Next.
-
In the Filters section choose which devices to import to Xurrent. By default, no devices are imported. You can choose to import devices based on the following criteria:
-
Once you have selected the filters you want to use, click Next.
-
In the "Review + Activate" section, review the settings you have chosen and click Activate.
Important
The connector will not start importing devices from Intune to Xurrent until you click Start in the resource view.
Configuration Settings
As part of the implementation of the Microsoft Intune connector for Xurrent a series of configuration options are provided to enable the enterprise to tailor the integration to their needs and business processes.
Filters
Using filters you can control which devices gets imported into Xurrent. By default, no CIs/devices gets imported but below is an explanation of each filter option you can use to control the import.
Configuration options | Description |
---|---|
Windows devices | Will if enabled import Windows devices registered in Intune into Xurrent. |
macOS devices | Will if enabled import macOS devices registered in Intune into Xurrent. |
ChromeOS devices | Will if enabled import ChromeOD devices registered in Intune into Xurrent. |
Import personally owned devices | This will, if enabled, import personally owned devices which reflects the way (and ownership) that the devices were added to Intune. By default, it means that the company is not responsible for the device but can enforce policies and settings on e.g., a phone to ensure it’s “protected”. This setting will have impact on the computer devices imported by the connector and not phones and mobile devices. |
User deleted for this device | If this filter is turned on (Off by default) devices which had the primary owner deleted will be imported into Xurrent. The name of the device will be “user deleted for this device” and there will be limited information about the device. |
Android devices | Will if enabled import Android devices registered in Intune into Xurrent. |
iOS devices | Will if enabled import iOS devices registered in Intune into Xurrent. |
Linux devices | Will if enabled import Linux devices registered in Intune into Xurrent. |
Require Primary User | This filter will, if enabled, only import users that has a primary user assigned to the device. If this is enabled, it will also filter out devices that “User deleted for this device. |
Behavior
The behavior section is used to control how the connector should behave when it encounters certain situations. The options are are described below.
Label configuration
There are two options that can be used for controlling how the Label property is set on CIs in Xurrent.
Option | Default | Description |
---|---|---|
Generated | The label is generated using the prefix of the other CIs and next available number. | |
Intune Device Name | The label is set to the name of the the device in Intune. |
Warning
If devices have been imported using the Intune Device name option, switching back to generated labels will only affect new CIs.
Name configuration
There are two options that can be used for controlling how the Name property is set on CIs in Xurrent.
Option | Default | Description |
---|---|---|
Intune Device Name | The name is set to the name of the the device in Intune. | |
Manufacturer + Model | The name is set to the Manufacturer and Model of the device in Intune. |
In Use Since configuration
There are two options that can be used for controlling how the In Use Since property is set on CIs in Xurrent.
Option | Default | Description |
---|---|---|
Enrolled Date | The In Use Since property is set to the date the device was enrolled in Intune. | |
Not set | The In Use Since property is not set and can be managed manually in Xurrent. |
Product mapping
Available in private preview
"Using QRatify to set products and categories" is currently in private preview and is not available for all customers. If you are interested in trying out this feature please contact support. Unless you're in the private preview you will not be able to see this section in the portal and the default option will be used "Using Xurrent to set products and categories".
The products section is used to control product mapping between Intune and Xurrent. The two general options are:
Using Xurrent to set products and categories (default)
When the Configuration Items are imported to Xurrent the connector tries to find existing Configuration Items in Xurrent using the serial number of the device. If a match is found the existing CI is updated with metadata from Microsoft Intune. If an existing CI isn’t found the connector creates a new CI as well as a simple product, representing the type of device. These products should be seen as a temporary product association until you have associated the CI with the product of your choice. You should also make sure that you associate your CIs with the correct Service and Service Instance.
Note
It’s very important that you associate your CIs with correct Services and Service Instances before enabling the Alerts functionality in the Intune Connector.
Using this option all Configuration Items will have the product and category set to Uncategorized in Xurrent on the first import. You can then set product and category manually in Xurrent or using your own automation rules.
Using QRatify to set products and categories
Using QRatify for product categorization will allow you to map the product and category based on the device manufacturer and model from Intune. Any unmapped devices will be imported to the Uncategorized product/category.
The QRatify platform tries to match the device manufacturer and model to the product and category in Xurrent. If a match is found you will see a Approve button. Clicking Approve will create the mapping and move it to the Categorized tab.
Alerts
The connector allows you to create Incidents based on Compliance Issues in Microsoft Intune to quickly raise awareness about possible security issues detected by Microsoft Intune.
By enabling Alerts, you will be able to take action on issues detected by Microsoft Intune in Xurrent. The connector will automatically create a Request in Xurrent on import after an compliancy issue has been detected and will continue to create a new Request every 24 hours until the issue is detected as resolved by Intune.
After enabling the feature the platform will evaluate your current state in Intune, showing you the current number of compliancy issues that would cause requests to be created in Xurrent. Once reviewed and accepted you can confirm and Save to activate the feature.
Note
It’s very important that you associate your CIs with correct Services and Service Instances before enabling the Alerts functionality in the Intune Connector. If this isn’t done the connector will not be able to associate the Request with the affected configuration item.
The Alerts feature is currently included for free but will consume an additional 850 tokens/month starting 1st of January 2025.
Summary Section
In the summary section there will be an overview of how many devices there is in total and toggling the different options will adjust the number of devices that will be imported with the given configuration. Once the right combination is found click Activate to enable the connector.