Skip to main content
See All Integrations

Microsoft Intune

Use selected Microsoft Intune device data in Pomerium policy through a custom external data source.

Custom customer-owned connector

Categories
Context Data Sources, Device Management

Overview

Microsoft Intune is a cloud endpoint and application management service. Microsoft Graph exposes Intune device inventory and compliance records. A customer-owned adapter can map selected fields to Pomerium Enterprise external data.

Selected Microsoft Intune data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium can evaluate selected Microsoft Intune records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.

How it works

Register a Microsoft Graph application with the minimum Intune read permissions. Obtain administrator consent. Read selected managedDevice records with paging and throttling controls.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

An adapter reads selected Intune compliance records and maps a reviewed organization state to a supported user key. Pomerium can evaluate that imported state. A managedDevice.id value alone does not prove which endpoint made the request.

Considerations

  • The tenant needs an active Intune license and administrator consent for the required Microsoft Graph application permissions.
  • Microsoft Graph paging, throttling, and field availability apply.
  • This is a customer-owned connector pattern, not a built-in Pomerium connector.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A vendor device or asset ID does not prove which device made the current Pomerium request.

Sources and official resources

  • Use selected Jamf Pro device data in Pomerium policy through a custom external data source.

  • Use selected Iru Endpoint Management device data in Pomerium policy through a custom external data source.

  • Use selected Kolide inventory records in Pomerium policy through a customer-owned external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo