← All integrations

Devices & MDM · integration

Microsoft Intune

Managed-device compliance and Microsoft Defender health for Microsoft Intune.

ISO 27001SOC 2PCI DSSDPDPARBISEBI CSCRFIRDAI

What ProofLayer proves

Read-only evidence, evaluated against versioned rules.

  • Devices are encrypted, compliant, patched (recent sync) and not jailbroken; a compliance policy is assigned
  • Windows devices have Microsoft Defender on and healthy (malware + real-time protection, current signatures)

Configure in ProofLayer

Live in minutes.

  1. Connections → New connection → pick this provider and name the account.
  2. Enter the directory (tenant) ID and your app registration (client ID + write-only secret), or use ProofLayer’s multi-tenant app.
  3. Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
  4. Set the scan schedule; every run appends to the evidence chain for this account.
  5. Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).

Grant access from your side

Read-only, least-privilege, revocable.

You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.

  1. Register an app with DeviceManagementManagedDevices.Read.All and DeviceManagementConfiguration.Read.All and grant admin consent.
  2. Create a client secret (pasted write-only).

In-account agent option. Run the agent with the app registration in AZURE_* env vars. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.

Start

Connect Microsoft Intune against your next audit.