The IDMS InTune connector requires additional configuration steps for the IDMS Microservice and InTune connectivity. This purpose of this document is to list what is required before the installation process occurs to ensure the installation can proceed smoothly. Do not install until all of the installation items are in place.
Connectivity
The installation of the InTune connector requires an additional Microservice that will process inbound SCEP requests from the InTune server
- The machine hosting the IDMS Microservice can be accessed from the public InTune server OR the IDMS Scep Relay service has been installed in location both the IDMS and InTune MDM can reach via the internet.
- The machine that will host the IDMS server is on a domain that can connect to the certificate authority.
- The certificate template for the derived credential is provided.
- The machine that will host the IDMS server can connect to the HID Credential Management System
- Server can connect to SQL Server and Active Directory
Accounts and credentials
The server and Microservice utilize PKI credentials to securely communicate with the internal infrastructure and InTune service. The following is required to ensure the systems can communicate.
- A client certificate exported to a PFX is available and is ready to install on the IDMS Microservice
- Create a CMS client certificate. Assign this client certificate “Help Desk” rights in the CMS. Install this client certificate in to the local computer store and mark key as exportable.
- Customer has both SSL and Client certificates installed in the local computer store and marked key as exportable.
- Dedicated account created and user is logged on as that account (admin role)
- Service account has the necessary database rights and operating system access to the PKI credentials
InTune configurations
The IDMS communicates with InTune to retrieve device information and to validate SCEP requests. When the installation is performed, IDMS will need the following configuration details and credentials
- Tenant ID
- Client ID
- User name of the operator with permissions to access the Azure Directory
- Password of the of the operator with permissions to access the Azure Directory
- Permissions granted to the application