intuneatlas login
Sign in to a tenant and confirm the token works.
| Flag | Description |
|---|---|
| --tenant <id-or-domain> | Tenant ID or domain, e.g. contoso.onmicrosoft.com |
| --client-id <id> | Your Entra app (client) ID — register one first. Omit it in a terminal and you'll be prompted once, then it's saved for next time. Can also come from INTUNEATLAS_CLIENT_ID (a per-run override, not saved). |
| --client-secret <secret> | Client secret — selects the unattended client-credentials flow instead of interactive sign-in |
| --device-code | Use device-code sign-in instead of the interactive browser flow |
Example
$ intuneatlas login --tenant contoso.onmicrosoft.com --client-id <application-id>
intuneatlas scan
Pull Windows Settings Catalog policies and build the settings index.
| Flag | Description |
|---|---|
| --tenant <id-or-domain> | Tenant ID or domain |
| --client-id <id> | Your Entra app (client) ID — register one first. Omit it in a terminal and you'll be prompted once, then it's saved for next time. Can also come from INTUNEATLAS_CLIENT_ID (a per-run override, not saved). |
| --client-secret <secret> | Client secret — unattended client-credentials flow |
| --device-code | Use device-code sign-in instead of the interactive browser flow |
| --out <path> | Write JSON to a file instead of stdout |
| --baseline <path> | Directory of baseline YAML rules (defaults to the bundled starter pack) |
Example
$ intuneatlas scan --tenant contoso.onmicrosoft.com --client-id <application-id> --out report.json
intuneatlas ui
Open the web UI. Always signs in with your own Microsoft account — that's what runs any scan you trigger.
| Flag | Description |
|---|---|
| --tenant <id-or-domain> | Tenant to sign in to — needed the first time, or to switch tenants |
| --client-id <id> | Your Entra app (client) ID — register one first. Omit it in a terminal and you'll be prompted once, then it's saved for next time. Can also come from INTUNEATLAS_CLIENT_ID (a per-run override, not saved). |
| --report <path> | Read a report from a prior scan --out instead of scanning live |
| --baseline <path> | Directory of baseline YAML rules (defaults to the bundled starter pack) |
| --host <address> | Interface to bind to (default: 127.0.0.1, this machine only). Anything else — e.g. 0.0.0.0 — shares it with a team; each teammate signs in with their own Microsoft account. |
| --persist | Register this exact command to run in the background, starting at boot and restarting on failure (Windows: Scheduled Task as SYSTEM; Linux: systemd service as root). Requires --tenant, --client-id, and an elevated/root shell — the background service can't prompt for either at boot, or read the client ID saved for your own interactive login. |
| --stop | Stop and remove a previously --persist'd background instance |
Solo, on your own machine
$ intuneatlas ui --tenant contoso.onmicrosoft.com --client-id <application-id>
Shared instance that survives reboots
$ intuneatlas ui --persist --host 0.0.0.0 --tenant contoso.onmicrosoft.com --client-id <application-id>
Stop and remove it
$ intuneatlas ui --stop
intuneatlas export
Export the last scan from local storage — never re-scans the tenant.
| Flag | Description |
|---|---|
| --tenant <id-or-domain> | Only export the latest scan for this tenant |
| --kind <kind> | settings (default), compliance, or enrollment |
| --format <format> | csv (default; only format available for now) |
| --out <path> | Write to a file instead of stdout |
Example
$ intuneatlas export --tenant contoso.onmicrosoft.com --kind settings --out settings.csv