jgeselle /IntuneAtlas
Docs

Getting started

Install the CLI, register an Entra app for it to sign in with, and get a searchable, conflict-checked settings index for one tenant.

Install

Both installers download a standalone binary — no Node.js required.

Windows
$ irm https://intuneatlas.com/install.ps1 | iex
Linux
$ curl -fsSL https://intuneatlas.com/install.sh | bash

Either one puts intuneatlas on your PATH. See the CLI reference for every command it adds.

Register an Entra app

IntuneAtlas doesn't ship with a bundled app registration — every install signs in with an app you register yourself, in your own tenant. It only takes a few minutes, and you only do it once.

  1. Go to portal.azure.com → Microsoft Entra ID → App registrations → New registration. Give it any name (e.g. "IntuneAtlas"); the default "Accounts in this organizational directory only" is fine unless you specifically need multi-tenant.
  2. Once created, copy the Application (client) ID from the overview page — that's what goes in --client-id below.
  3. Authentication → Add a platform → Mobile and desktop applications.
  4. Add a Custom redirect URI (not one of the predefined options):
    http://localhost:7878/auth/callback
    Use localhost, not 127.0.0.1.
  5. Add a second Custom redirect URI, same platform, no port or path:
    http://localhost
    Used by intuneatlas login/scan. Skip it if you only use --device-code.
  6. API permissions → Add a permission → Microsoft Graph → Delegated permissions → add these four, all read-only: DeviceManagementConfiguration.Read.All, DeviceManagementManagedDevices.Read.All, Organization.Read.All, and DeviceManagementServiceConfig.Read.All. If you're a Global or Intune admin, click Grant admin consent now — otherwise the first sign-in will prompt for it instead.
  7. App roles → Create app role, three times, one for each of: viewer (browse only), contributor (+ notes, staging and managing your own changes), and admin (+ triggering scans, managing everyone's changes). For each: Allowed member types → Users/Groups, Value exactly the lowercase name above.
  8. Microsoft Entra ID → Enterprise applications → your app → Users and groups → Add user/group, and assign yourself (and anyone else who'll use it) to one of the three roles. Required — skip it and you'll get a "no role assigned" screen with nothing to do.
  9. Same app → Properties → Assignment required? → Yes.

Sign in and run your first scan

  1. Run:
    $ intuneatlas ui --tenant contoso.onmicrosoft.com
    No client ID registered yet on this machine? You'll be prompted for the Application (client) ID from the app you just created — paste it in once and it's saved (~/.intuneatlas) for every future command, on any tenant. Prefer to skip the prompt entirely, or set it up non-interactively? Pass --client-id <application-id> instead — same effect, and it also works as the way to change the saved one later.
  2. A browser window opens to a normal Microsoft sign-in screen. Sign in with your own account — this is the same account and permissions used for every scan and change review from here on.
  3. Once signed in, the scan runs and the web UI opens automatically at http://localhost:7878. Reopening ui later reuses the cached sign-in on Windows and macOS; on Linux it prompts again each time.
Scripts and CI. The prompt only ever appears in a real interactive terminal — piped or non-interactive stdin skips it and fails fast instead of hanging. Always pass --client-id explicitly there, or set INTUNEATLAS_CLIENT_ID (a per-run override, not saved to disk).

What you get

The web UI shows every Windows Settings Catalog, compliance, and enrollment setting from the scan, merged across policies by the real setting — with conflicts between overlapping policies and coverage gaps against a baseline surfaced directly, instead of buried across per-policy views.

It's read-only end to end: IntuneAtlas never writes anything back to the tenant.

Sharing it with a team

--host 0.0.0.0 turns the same server into a shared instance — everyone who connects signs in with their own Microsoft account, and what they can do once signed in follows the App Role you assigned them (above): Viewers can browse, Contributors can also add notes and manage their own staged changes, and only Admins can trigger a new scan or manage anyone's changes.

Shared mode needs a real HTTPS hostname reachable by your teammates' browsers — a plain LAN IP over HTTP won't work. A reverse proxy with a certificate (Caddy is the simplest option) or any host that terminates TLS both work. Then add https://<hostname>/auth/callback as another Custom redirect URI on your app's Authentication page, alongside the localhost one.

--persist registers that exact command to keep running across reboots — a Scheduled Task on Windows, a systemd service on Linux. See the CLI reference for the full flag list.

Next