This article walks you through connecting Microsoft Intune to SuperOps, so you can automatically discover your organization's Intune-managed devices, view Intune compliance data, and bring supported endpoints under full SuperOps management, all without leaving SuperOps.
Overview
Intune remains the system of record for enrollment, compliance policy, and MDM control for every device you manage through it. SuperOps connects to Intune to:
Automatically discover those devices
Sync their compliance status
For supported operating systems, deploy the SuperOps agent so your team can patch, monitor, and remotely support them like any other SuperOps-managed device
What gets discovered
Once connected, SuperOps discovers all Intune-managed devices in the groups you select, across the following device types:
Windows
macOS
Linux
iOS
iPadOS
Android
Windows, macOS, and Linux
You can choose to have the SuperOps agent deployed automatically. This helps in ensuring that no devices in Intune go unmanaged.
Once the agent is installed, the device is fully managed in SuperOps: patching, monitoring, alerting, scripting, remote access, and ticketing all work exactly as they would for any other SuperOps asset.
iOS, iPadOS, and Android
The MDM profile and all device management stay in Intune.
SuperOps gives you visibility into these devices and their Intune compliance status.
SuperOps does not take over MDM controls for these devices.
Before you start
You'll need:
An active Microsoft Intune tenant.
Admin credentials with sufficient privileges to grant consent (Intune Admin or Global Admin, as applicable) for that tenant.
The corresponding site already created in SuperOps.
Setting up the integration
In SuperOps, go to Settings → Integrations → Microsoft Intune.
Toggle On the button in the top right corner to get started with the integration.
Creating a Device Discovery Plan
A Discovery Plan tells SuperOps which Intune device groups to pull from, and which SuperOps site to route them into. Click on "New discovery" in the integration page to get started.
Step 1: Authenticate.
Sign in with a Microsoft admin account for the tenant you're connecting.
Select the Microsoft Tenant Name. The Microsoft Tenant ID is filled in automatically once you do.
Select the Site you want devices routed into.
Step 2: Map groups from Intune.
Click Re-authenticate with the same Microsoft account to fetch the available groups within that tenant.
Search for and select one or more Intune device groups. You'll see a summary explaining that the SuperOps agent will be automatically installed on all existing and newly added devices in the groups you select, for Windows, Linux, and Mac devices.
If you'd rather discover devices without installing the agent, turn off Deploy agents to all discovered devices. You can always enable agent deployment on a plan later.
Click Finish to save the plan.
What happens if the device already has a SuperOps agent?
Each device's identity is checked when the agent registers, so if it matches a device already discovered through Intune, the existing record is updated rather than a new one being created. Whether the agent installs before or after a device has been discovered through Intune, SuperOps automatically links the two together as a single asset. You won't end up with duplicate records for the same device.
The match is checked against, in order: Intune device ID, hardware identity (serial number, system UUID, disk serial), MAC address, and serial number as a fallback. The first match found is used to link the agent to the existing device.
A few things worth knowing:
You can create multiple Discovery Plans, for example, to route different device groups to different sites, or to run agent deployment on one group while keeping another as discovery-only.
Once a plan is active, SuperOps checks Intune every 12 hours to discover new devices and keep existing ones in sync.
Intune visibility within the device
Once a device is discovered, navigate to the asset record to see the Intune compliance details.
On the summary page, you will find an Intune card where you will see the compliance status.
Click "More info" or navigate to the "Details" section → Intune information to see an Intune Information panel:
Intune compliance details, such as the device's compliance status by policy
General information, such as the enrollment date and operating system
A deep link to Intune is available here, so technicians can navigate and troubleshoot faster.
This information is synced every 6 hours.
Note: If the device's Intune-assigned user's email matches a requester in the corresponding site in SuperOps, that requester is automatically linked to the device.
On the main asset list, the Intune Compliance column shows each device's compliance state at a glance, so you can quickly spot non-compliant devices and filter them out for action.
FAQs
1. Does this replace Intune?
No. Intune continues to manage enrollment, compliance policy, and MDM actions for every device. SuperOps adds visibility and operational management on top.
2. How are MDM devices like iOS and Android handled?
iOS, iPadOS, and Android devices are discovered and their Intune compliance data is visible in SuperOps. MDM-related actions, such as remote wipe, lock, or restart, remain with Intune.
3. What happens if the Intune connection needs to be reauthorized?
Reconnecting refreshes the sync going forward. Existing discovered devices and their data are not affected.
4. Can a device accidentally get moved to a different site?
No. If a device already belongs to a site in SuperOps, an automated Intune install can't move it elsewhere.
5. What happens if I delete a device that's still enrolled in Intune?
Once you delete an asset in SuperOps, it stays deleted. It won't be automatically recreated by future syncs or agent installs.
