Loading

Microsoft Intune Integration for Elastic

Version 0.1.0 (View all)
Subscription level
What's this?
Basic
Developed by
What's this?
Elastic
Ingestion method(s) Azure Event Hub
Minimum Kibana version(s) 9.0.0
8.18.0
The Microsoft Intune integration v0.1.0 is in beta

To use beta integrations, go to the Integrations page in Kibana, scroll down, and toggle on the Display beta integrations option.

Microsoft Intune is a cloud-based endpoint management solution that helps organizations manage and secure their devices, applications, and data. It provides comprehensive mobile device management (MDM) and mobile application management (MAM) capabilities for iOS, Android, Windows, and macOS devices.

The Microsoft Intune integration for Elastic allows you to collect audit and managed device logs using Azure Event Hub, then visualize the data in Kibana. This integration provides visibility into device management activities, policy compliance, application deployments, and security events across your Intune-managed environment.

The Microsoft Intune integration uses Azure Event Hub to collect audit and managed device logs from Microsoft Intune.

This integration collects audit and managed device logs from Microsoft Intune by consuming events from an Azure Event Hub. Intune audit and managed device logs are forwarded to the Event Hub, and the Elastic Agent reads these events in real-time, processes them through ingest pipelines, and indexes them in Elasticsearch.

This integration collects Microsoft Intune audit and managed device logs.

Integrating device inventory data and Microsoft Intune audit logs into SIEM dashboards provides a unified view of endpoint posture and administrative activity. It highlights device attributes like OS, ownership, and compliance status alongside audit insights such as total events, success vs. failure trends, top operations, and active actors. Combined breakdowns by actor type and context, along with detailed inventory and audit records, enable quick assessment, efficient investigation, and improved governance and security monitoring.

  • Set up Azure Event Hub for Intune Audit Logs and Managed device logs and send audit logs and managed device logs from Intune to Azure Event Hub. For more detail, refer to the link here.
  • Note:
    • Audit: Select LOG > AuditLogs.
    • Managed Device: Select LOG > IntuneDevices.

This integration supports Agent-based installations.

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions. You can install only one Elastic Agent per host.

  1. In Kibana navigate to Management > Integrations.
  2. In the search bar, type Microsoft Intune.
  3. Select the Microsoft Intune integration and add it.
  4. While adding the integration, to collect logs via Azure Event Hub, enter the following details:
    • eventhub
    • consumer_group
    • connection_string
    • storage_account
    • storage_account_key
    • storage_account_container (optional)
    • resource_manager_endpoint (optional)
  5. Select Save and continue to save the integration.
  1. In the top search bar in Kibana, search for Dashboards.
  2. In the search bar, type Microsoft Intune.
  3. Select a dashboard for the dataset you are collecting, and verify the dashboard information is populated.

For more information on architectures that can be used for scaling this integration, check the Ingest Architectures documentation.

This is the managed_device dataset.

This is the audit dataset.

These inputs can be used in this integration:

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.