Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Integrate MS Intune

Prev Next

Connect your Microsoft Intune (MS Intune) account with Scrut to automatically pull employee device data into your compliance workflows. In this guide, we walk you through connecting your Microsoft Intune account to Scrut.

What This Integration Does in Scrut

  • User Endpoint Devices: Fetches employee device details, including security posture and installed software. These devices are mapped to employees and visible in their profile under People → Employees → Technical.

  • Automated Tests: Runs automated compliance checks that continuously evaluate your device configurations against applicable compliance frameworks.

  • Scrut Monitor: Collects evidence through Scrut Monitor. This helps automate evidence gathering and significantly speeds up compliance workflows.

  • Asset Management: Populates the Asset Management module in Scrut with discovered devices and supports the collection of asset-related compliance evidence.

Prerequisites

  • An active Microsoft Intune account with administrator access

  • Devices enrolled and managed in Microsoft Intune

Why is administrator access required?

For the Scrut integration to work, it requires an administrator-level role (Global, Application, or Cloud Application Administrator) to grant the necessary tenant-wide, read-only permissions.

Permissions and Access Requirements

For MS Intune

Scrut requires the following read-only OAuth scopes during authorization:

  • openid

  • offline_access

  • https://graph.microsoft.com/User.Read.All

  • DeviceManagementManagedDevices.Read.All

  • DeviceManagementConfiguration.Read.All

Note: Refer to Microsoft's documentation for details on each permission scope.

For Scrut

  • Admin access to Scrut, or Contributor access with the Integration module enabled

Data Collected

Scrut fetches the following details for each device in your MS Intune account:

  • Device name

  • OS version

  • Serial number

  • Antivirus installed (Displayed as Yes/No)

  • HD Encrypted (Displayed as Yes/No)

  • Screenlock Enabled (Displayed as Yes/No)

  • List of installed applications

Sync Frequency

Data syncs automatically every 24 hours. You can also trigger a manual sync from the MS Intune integration page.

Integration Setup

Step 1: Connect MS Intune in Scrut

  1. Sign in to Scrut and click Integrations in the left navigation panel.

  2. Click the Integrations Library tab.

  3. Under Categories, select Mobile Device Management (MDM) Tools.

  4. Locate the MS Intune tile and click Integrate.

  5. On the MS Intune integration page, click Connect in the top right.

  6. You are redirected to Microsoft's authentication page. Sign in with your Microsoft administrator account if prompted.

  7. On the Microsoft OAuth screen, review the requested permissions. Select the Consent on behalf of your organization checkbox and click Accept.

  8. Watch for the success notification and confirm the status changes to Connected.

Step 2: Configure Scope

  1. On the MS Intune integration page, click Configure Scope.

  2. Select the device checks you want Scrut to monitor:

    • Screen Lock Enabled

    • Antivirus Installed

  3. Click Save.

What Happens Next?

Initial data sync

Scrut begins syncing device data from Microsoft Intune after the integration is connected. Full data population may take some time, depending on the size of your device inventory. Monitor sync progress in the Audit Log on the MS Intune integration page.

Review synced data

  • Navigate to People → Employees → Technical to view employee device records and security posture data.

  • Navigate to Asset Management to view devices populated from MS Intune.

  • Navigate to Compliance → Evidence Tasks to set up a Scrut Monitor to automate evidence collection from MS Intune.

  • Navigate to Tests to view automated test coverage driven by MS Intune data. Apply the Application filter with MS Intune selected to view only MS Intune tests.

Common Errors & Troubleshooting

Authentication failure

Cause: The Microsoft account used during authorization does not have administrator privileges, or the consent checkbox was not selected.

Possible solutions:

  • Confirm you are signing in with an account that has the Global Administrator or Intune Administrator role in Microsoft Entra ID.

  • Repeat the authorization flow and ensure Consent on behalf of your organization is checked before clicking Accept.

Device data not appearing in Scrut

Possible solutions:

  • Check the Audit Log on the integration page to confirm the sync completed without errors.

  • Confirm that devices are enrolled and active in your Microsoft Intune account.

  • Trigger a manual sync by clicking Sync Now on the MS Intune integration page, and check again after a few minutes.

Device check fields show no data

Cause: The device check policies may not be configured in the Configure Scope step, or the relevant policies are not assigned in Intune.

Possible solutions:

  • Go to the MS Intune integration page, click Configure Scope, and confirm your desired checks are selected and saved.

FAQs


1: What happens if a device is removed from Microsoft Intune?

Devices removed from Intune are no longer synced to Scrut after the next scheduled sync. Existing records in Scrut are not automatically deleted.

2: Can I sync data more frequently than every 24 hours?

Scrut syncs device data every 24 hours on a recurring schedule. For an immediate update, click Sync Now on the MS Intune integration page to trigger a manual sync.

3: What does "Consent on behalf of your organization" mean?

Selecting this grants Scrut read-only access to device and user data across your entire organization, not just your own account. Administrator-level access in Microsoft Entra ID is required to grant this consent.

4: How do I find the synced device data in Scrut?

Device data appears in People → Employees → Technical within each employee's profile. Asset-level data is available in the Asset Management module.

Reach out to support@scrut.io or contact your CSM for further assistance.