Install
Both installers download a standalone binary — no Node.js required.
$ irm https://intuneatlas.com/install.ps1 | iex
$ curl -fsSL https://intuneatlas.com/install.sh | bash
Either one puts intuneatlas on your PATH. See the CLI reference for every command it adds.
Register an Entra app
IntuneAtlas doesn't ship with a bundled app registration — every install signs in with an app you register yourself, in your own tenant. It only takes a few minutes, and you only do it once.
- Go to portal.azure.com → Microsoft Entra ID → App registrations → New registration. Give it any name (e.g. "IntuneAtlas"); the default "Accounts in this organizational directory only" is fine unless you specifically need multi-tenant.
-
Once created, copy the Application (client) ID from the overview page —
that's what goes in
--client-idbelow. - Authentication → Add a platform → Mobile and desktop applications.
-
Add a Custom redirect URI (not one of the predefined options):
http://localhost:7878/auth/callback
Uselocalhost, not127.0.0.1. -
Add a second Custom redirect URI, same platform, no port or path:
http://localhost
Used byintuneatlas login/scan. Skip it if you only use--device-code. -
API permissions → Add a permission → Microsoft Graph →
Delegated permissions → add these four, all read-only:
DeviceManagementConfiguration.Read.All,DeviceManagementManagedDevices.Read.All,Organization.Read.All, andDeviceManagementServiceConfig.Read.All. If you're a Global or Intune admin, click Grant admin consent now — otherwise the first sign-in will prompt for it instead. -
App roles → Create app role, three times, one for each of:
viewer(browse only),contributor(+ notes, staging and managing your own changes), andadmin(+ triggering scans, managing everyone's changes). For each: Allowed member types → Users/Groups, Value exactly the lowercase name above. - Microsoft Entra ID → Enterprise applications → your app → Users and groups → Add user/group, and assign yourself (and anyone else who'll use it) to one of the three roles. Required — skip it and you'll get a "no role assigned" screen with nothing to do.
- Same app → Properties → Assignment required? → Yes.
Sign in and run your first scan
-
Run:
$ intuneatlas ui --tenant contoso.onmicrosoft.comNo client ID registered yet on this machine? You'll be prompted for the Application (client) ID from the app you just created — paste it in once and it's saved (~/.intuneatlas) for every future command, on any tenant. Prefer to skip the prompt entirely, or set it up non-interactively? Pass--client-id <application-id>instead — same effect, and it also works as the way to change the saved one later. - A browser window opens to a normal Microsoft sign-in screen. Sign in with your own account — this is the same account and permissions used for every scan and change review from here on.
-
Once signed in, the scan runs and the web UI opens automatically at
http://localhost:7878. Reopeninguilater reuses the cached sign-in on Windows and macOS; on Linux it prompts again each time.
--client-id explicitly there, or set
INTUNEATLAS_CLIENT_ID (a per-run override, not saved to disk).
What you get
The web UI shows every Windows Settings Catalog, compliance, and enrollment setting from the scan, merged across policies by the real setting — with conflicts between overlapping policies and coverage gaps against a baseline surfaced directly, instead of buried across per-policy views.
It's read-only end to end: IntuneAtlas never writes anything back to the tenant.
Next
- CLI reference — every command and flag
- Source on GitHub — issues, baselines, and the full history
- MIT license