Before configuring UEM Connect for Microsoft Intune, you must have:
Jamf Security Cloud administrator access
iOS, Android, or Windows devices that are managed by Microsoft Intune
Azure Microsoft Intune Portal 10.3.3451.0 or later.
Access to an account with Azure Portal Privileged or Global Administrator permissions:
An Azure Administrator must grant Jamf Security Cloud permissions to your Azure and Microsoft Intune tenant account.
- Global Administrator is required for Jamf Protect's endpoint and network security service (formerly Threat Defense). The administrator specifically needs . This permission can be granted to apply the admin consent to the application, and after this is done it can be removed from the account. The application should continue working normally and it only needs this permission once.Note:
For the admin grant to remain valid, the administrator's device must stay in the UEM. If the administrator's device is removed from the UEM, the grant token will fail, and a "400" error will be returned. If this situation occurs, the admin must grant consent again to ensure their device remains enrolled in the UEM.
The ability to create network firewall exceptions.
The following table shows the Entra ID roles needed for certain UEM Connect features.
UEM Connect Feature Required Entra ID Role Microsoft Intune user and device sync At least one of the following:- Global Administrator
- Application Administrator and Security Reader
Mobile Threat Defense Global AdministratorNote:Global Administrator privileges are required for initial configuration and can be removed from the Entra ID account once UEM Connect is set up.
Device UEM signaling At least one of the following:- Global Administrator
- User Administrator
- Custom role:
User.ReadplusGroupMember.ReadWrite.All