Configuring the Intune Connector

Configuring the Intune Connector

Purpose

Guide customers through the process of configuring the Entra ID App Registration and the settings in the Lenovo Patch plugin.

Process

Configuring Entra ID

  1. Login to Entra ID.

    Entra ID App Registration
  2. Navigate to the Applications > App Registrations node.

    Entra ID Register Application
  3. Click on the '+ New Registration' link.
  4. On the 'Register an application' screen, provide a name
  5. For the remaining options, make selections relevant to the organization.
  6. Click the 'Register' button to create the App Registration.
  7. From the list of App Registrations, select the App Registration that was just created.

    Entra ID App Reg API Permissions
  8. Navigate to 'API Permissions' and click the '+ Add a permission' link.
  9. Select Microsoft Graph.
  10. On the 'Request API permissions' screen, click Delegated permissions.
  11. From the 'Select permissions' section, place a check mark by:
    1. Directory.Read.All
    2. Directory.ReadWrite.All
  12. Click the 'Add Permissions' button.
  13. On the 'Request API permissions' screen, click Application permissions.
  14. From the 'Select permissions' section, place a check mark by:
    1. Application.Read.All
    2. Application.ReadWrite.All
    3. DeviceManagementApps.ReadWrite.All
    4. Directory.Read.All
    5. Directory.ReadWrite.All
    6. GroupMember.Read.All
    7. GroupMember.ReadWrite.All
  15. Click the 'Add Permissions' button.

    Entra ID App Registration Configured Permissions
  16. After granting the permissions, an Entra ID administrator will need to click the 'Grant admin consent for …' button on the 'Configured permissions' screen.

    Entra ID App Registration Admin Consent Granted
  17. Once the Entra ID administrator has granted consent, the status should reflect the changes as above.

    Entra ID App Registration Information
  18. Obtain the Application ID GUID, Directory (tenant) ID GUID, and the secret information to use in the next section to configure the Lenovo Patch settings.

 

Configuring Lenovo Patch Settings

  1. In the Configuration Manager console, navigate to Software Library > Overview > Software Updates > Lenovo Patch > Updates.
  2. In the ribbon bar, click on 'Settings'.

    Lenovo Patch Settings Application Management Tab
  3. Click on the 'Application Management' tab.
  4. Configure the 'Application source folder' using a UNC path to a folder to contain the source media for the application installers.
  5. Enable the checkbox by 'Enable Intune publishing'.
  6. In the 'Tenant domain' text box, enter the GUID from the Directory (tenant) ID from step 14 above.
  7. In the 'Application ID' text box, enter the GUID from the Application ID from step 14 above.
  8. In the 'Client secret' text box, enter the secret from step 14 above.
  9. Click the 'Test connection' button to test the connection to Intune.
  10. Upon success, click the 'OK' button to save the settings.