The Intune integration allows IT teams to view all devices and users within their organization. By having this data within FMX, these IT teams can create tickets on their behalf, and audit what they have available.
This article will explain how to set up your Intune integration with FMX for your users. These instructions are for users who have purchased the Intune integration and have already been added to prismatic. If you are interested in adding this integration please reach out to your account manager at FMX. Once an FMX team member reaches out you can begin the process with the below steps.
Create Integration User
Skip this step if you already created the FMX integration user for the Intune device integration.
You will need to create an account in your FMX site for the integration to sync with. Name the account "Intune Syncer" this will make it easier to track the users brought over to FMX. Use the email "Intune-syncer@gofmx.com". In order to do this you will need to create a new user type that will not be updated. If the integration’s user type is updated this can cause the integration to not work.
To create a new user type click the “Admin Settings" in the left sidebar then select the” User Types" tab at the top of the page. You can either select add “User Type” at the top of the page or click the vertical 3 dots next to a user type that may have full access like “FMX Administrator” and click “copy”. Name the user type “FMX Integration”. For more information on user types go to this support center article.
Next go to the following settings and make sure the user type has the following permissions:
-
Building & Resource Access
- Read - Any
-
Equipment Access
- Create
- Read - Any
- Update- Any
- Retire - Any
-
Permitted Equipment Types Includes All Desired
- If the user type does not have access to an equipment type you would want to sync with Intune then those devices will not sync.
-
User & Contact Access
- Administer
- Read Users
- Read Contacts
- Delete
- Permitted Access to All Desired Custom Fields
You will use this information in the configuration step below.
Add Custom Fields
Add the customs required custom fields in your FMX site before starting the integration steps. The custom fields need to be in FMX prior to the steps being completed so that you will be able to map the correct Intune field to correct FMX field.
Add the following field:
- Link to Intune: add this custom field for users & contacts that is a text field. Make sure that you do not limit the permitted user types or exclude any of the user types you want map over for this field so that the integration can work properly.
Additionally, there are optional custom fields you can map over from Intune to FMX. See below for fields you can add prior to the integration setup. These fields can be added later and the integration can be updated. The FMX custom fields need to be text fields. They also need to be available for the equipment types you are syncing with Intune. The field mapping section of the article explains more. The required field above is needed for the integration to work.
When creating a custom field make sure include all the integration user type in the permitted user types section or leave it blank so all user types will be included.
Optional fields:
- Business Phone
- Job Title
- Preferred Language
**See this support center article for how to add custom fields in FMX**
Intune Authentication Setup
**If you have already done this for the Intune device integration you do not need to do this again**
Follow the below steps for Intune authentication. This is needed for when you go to set up the integration in FMX.
Go to your Azure portal: https://portal.azure.com/#home
- In the search bar at the top of the page, search for “Intune.” In the drop down results, scroll down to the Microsoft Entra ID section and select the Intune Application.
-
Navigate to Manage > Authentication
- Add a platform and choose Web under Web applications
- Add “https://oauth2.prismatic.io/callback” into the Redirect URIs and click “Configure”
- In the Implicit grand and hybrid flows section, select Access tokens (used for implicit flows)
- In the Support account types section, select Accounts in any organization directory (Any Microsoft Entra ID tenant - Multi-tenant)
-
Navigate to Certificates and secrets
- Under Client Secrets, add a new client secret
-
Enter a description and choose the desired expiration date.
- Once this client secret expires, a new client secret will need to be created and the Intune-FMX integration will need to be reconfigured with the new client secret.
- Save the Secret ID value for the Client Secret in the Microsoft Intune Connection configuration in the Intune - FMX integration.
- Navigate to the Overview page and save the value listed as the Application (client) ID. This will be your Client ID for the Microsoft Intune Connection configuration in the Intune-FMX integration.
-
Navigate to Manage > API permissions
- Add a permission and choose Microsoft Graph
-
Choose Delegated permissions and add the following permissions:
- DeviceManagementApps.Read.All
- DeviceManagementManagedDevices.Read.All
- Group.Read.All
- GroupMember.Read.All
- User.Read.All
- Offline_access
- Based on your company’s settings, status may need to be granted by your admin
Intune Group Setup
The integration allows users to map FMX equipment types and FMX buildings to Intune groups. Devices per group are based on the devices registered for the members of that group.
- To add new groups of devices for the Intune Device Integration:
- Go to https://intune.microsoft.com/#home
- Navigate to Groups and add a new group
- Set up the required fields
- Under Members, select the members whose device will show up under this group
- Useful links for more information on how to manage a group in Intune:
- Devices will need to be registered in Intune. Useful links on how to enroll devices in Intune:
Go to the Integrations Settings
A member of the FMX team will reach out to you when your integration has been added to your FMX site.
In your FMX site go to your admin settings. Then go to the tab that says “Integrations”. In this section you will see all of the integrations you have on your FMX site through Prismatic. Prismatic is a platform that you will use to set up the integration between Intune and FMX. The platform is embedded into FMX and you will use it via the integrations tab. To access your integration to begin the setup process select the integration you would like to work on. If you do not see the Intune integrations reach out to your primary contact at FMX.
Intune Users
Go to the integrations settings tab in your admin settings. To set up the Intune integration for your users select the “Intune - Users" in this tab. In order to start this process click the “Reconfigure” button.
1. Initial Configuration
For this step there is nothing that you need to do to complete this. Select "Next" to move on to the configuration section.
2. Configuration
**If you set up the Intune device integration first use the same "Client ID", "Client Secret", "Hostname", "API User Password", and "API User Email" in this section. **
Next fill out the Client Id and Client Secret. These were gathered in the above authentication steps. Once those are fields are fill out. Select the "Connect" button to connect the integration.
Next, fill out the following fields in the FMX API Connection section:
- Hostname - this is your FMX hostname. This can be found in the URL of your site and it is the text before “.gofmx.com”. For example: https://fmxschool.gofmx.com/. The bolded text is your hostname.
- Password - this is the password of the FMX integration user you add
- API User Email - this is email address of the integration user you add
Select the "Next" button when you are finished.
3. User Mapping
In this section you will select which user groups from Intune you want to include in the integration, as well as their respective user type in FMX, and whether they should be added as a user or contact. Only groups selected below will be synced with FMX.
In the type mapping section choose an "Intune Group" from the first drop down, then select corresponding FMX user type from the "FMX User Type" dropdown. Then choose whether you want them to be a user or contact in FMX.
Choose to "Override Existing User Permissions" or not. When the box is checked the above user type and user/contact selection will be applied to existing users in FMX belonging to this Intune group. Otherwise, they will only be applied to new users.
Choose to "Override Existing Accessible Building" or not. When the box is checked the accessible building mapped in the next step will be applied to existing users in FMX belonging to this Intune group. Otherwise, it will only be applied to new users.
Continue this process for all the Intune users you would like to do this for by selecting the "+ Add to Intune Group Mapping" button to add more.
Select the "Next" button when you are finished.
4. Accessible Building Mapping
Each Intune Group can be mapped to multiple accessible buildings in FMX. This mapping is ONLY for users with at least one permission set to "accessible buildings" in FMX. Users who only have permissions set to "any building" will be mapped automatically and do not need to be mapped on this page.
Select the "+ Add to Accessible Buildings Mapping" to match each "Intune Group" with a respective building in FMX. Only mapped groups from the previous step will show in the Intune Group dropdown list. These mappings will be used when assigned accessible buildings in FMX. Continue this process until all of the buildings are mapped. If a user group has multiple accessible buildings, please add each additional building as a new line with that same Intune group. Select the next button when you are finished.
5. Field Mapping
In this section you will map the fields from Intune to custom fields in FMX.
In the first field choose an Intune field to use for the alternate invoice email in FMX. This is optional and is used with the FMX invoice module. To learn more about this field see this support article. This field can be updated later as well.
Next choose the user custom field in FMX(this was added in an earlier step) that you want the "Link to Intune URL" to map to.
Next select the "+Add to Optional Custom Fields" button choose from the optional Intune fields listed in the drop down to map to an FMX custom field by matching the fields in each drop down menu. If you did not create custom fields for these prior to configuration in FMX you can reconfigure the integration to map these later. Continue this process until the fields you would like have been mapped. Do not map the same field twice. Select the "Finish" button when you are done.
Updating the Integration
If changes need to be made to your integration you can update it at any time. To do this go back to the Integration Settings tab in FMX. Then find the integration and select "Reconfigure". Make your updates and click Next to the last page of the configurations, and clicking the Finish button will ensure your changes are saved.
See this support article to setup the Intune device integration.