Get startedBefore you start

Before you start

What you need before you install the desktop app: a supported computer, a license, the right admin roles and about ten minutes.

Setting up the desktop app takes about ten minutes from download to your first export. Most of that time is spent once, in Microsoft Entra, creating the app registration the app signs in with. This page lists everything you need so the setup runs without interruptions.

What you need at a glance

You needWhy
A Mac or Windows PC that meets the system requirementsThe app runs and stores everything on this computer.
A license key, or a colleague who already shares a license with your tenantCollecting and exporting need an active license for the signed in tenant.
Someone who can create an app registration in Microsoft EntraThe app signs in through an app registration that lives in your own tenant.
Someone who can grant admin consentThe read-only Microsoft Graph permissions need a one-time tenant-wide consent.
An account that can read Intune and Conditional AccessThe app only sees what the signed in account is allowed to see.
Internet access to Microsoft Graph and to the licensing serviceCollection talks to Microsoft directly. License checks go to intunedocumentation.com.

System requirements

PlatformSupported versions
macOSmacOS 13 Ventura or later, on Apple Silicon or Intel
WindowsWindows 10 or 11, 64-bit (x64)

The machine needs internet access to Microsoft Graph for collection. See Install the desktop app for the download for your platform.

A license

You need a Pro or MSP license to collect and export. The key arrives by email right after checkout, and every plan comes with a 30-day money-back guarantee.

  • Compare the plans on Plans and billing, or buy directly on the pricing page.
  • If a colleague already activated a shared license for your tenant, you do not need a key. The app finds the license when you sign in.

You can also finish the setup without a key and add it later under License and account.

Who needs to do what

Setting up involves up to three roles. In a small team one person often does all of it. In a larger organization, you may need to ask an Entra administrator for the middle part.

Create the app registration

Someone who is allowed to register applications in your tenant creates the registration, adds the redirect address and adds the permissions. By default in Microsoft Entra ID every user can register applications. If your organization has turned that off, the person needs the Application Developer, Application Administrator or Cloud Application Administrator role.

A Global Administrator, Privileged Role Administrator or Cloud Application Administrator grants tenant-wide consent for the nine read-only permissions. This happens once per tenant.

Sign in and use the app

Everyone who uses the app signs in with their own account. That account needs read access to the areas you want to document, as described in the next section.

Someone else does the Entra part?

Send them the page Create the app registration. It covers creating the registration, adding the platform, adding the permissions and granting consent. When they are done, ask for the Application (client) ID and the Directory (tenant) ID from the registration's Overview page. Neither value is a secret.

Roles for reading your configuration

The app never writes to your tenant. It reads with your own sign in, and it only sees what your account can read.

  • Security Reader or Global Reader each cover everything the app reads.
  • Intune roles such as Intune Administrator or Read Only Operator cannot read Conditional Access policies. Pair them with Security Reader.

If your account is missing access to an area, the app still collects everything else and lists the gaps after collection. See Troubleshooting.

Network access

The app needs to reach two places:

  • Microsoft, to sign in and to read your configuration through Microsoft Graph.
  • The licensing service at intunedocumentation.com, to activate and check your license. After a successful check, the app keeps working for 14 days without reaching it.

If your organization uses a proxy, HTTPS inspection or a web filter, ask IT to allow the licensing service in advance. The exact address is listed under Troubleshooting.

Security approval

If your security team needs to approve the app first, send them the one-page security overview (PDF) and the Security and privacy page. In short: the app registration lives in your own tenant, uses delegated read-only permissions and gives us no access to your tenant.

Checklist

Before you begin, check that you have:

  • A Mac with macOS 13 or later, or a Windows 10 or 11 PC (64-bit)
  • A license key from your purchase email, or a colleague who shares a license with your tenant
  • Permission to register applications in Microsoft Entra, or someone who can do it for you
  • A Global Administrator, Privileged Role Administrator or Cloud Application Administrator who can grant admin consent
  • An account with Security Reader or Global Reader, or an Intune role plus Security Reader
  • Internet access to Microsoft and to intunedocumentation.com
  • About ten minutes

Next steps

  1. Install the desktop app
  2. Create the app registration
  3. Sign in and activate your license

On this page