Prerequisites for connecting to Microsoft Intune
Last updated September 1st, 2026
We recommend Intune customers to use Knox E-FOTA directly on the Microsoft Intune admin center, allowing you to use Knox E-FOTA firmware management features without leaving the Microsoft Intune admin center.
For information about using Knox E-FOTA directly on Microsoft Intune, see:
This section describes prerequisite procedures you need to perform before you can sync device groups from Microsoft Intune to the Knox E-FOTA console.
To connect to Microsoft Intune, you need:
- A Microsoft Intune account
- A client ID
- A tenant ID
- A client secret
Step 1: Create a client ID and a tenant ID
-
Sign in to https://portal.azure.com.
-
Click More services.
-
Under Identity, click App registrations.
-
On the main screen, click New registration.
-
Enter a name for this application, for example, Knox E-FOTA.
-
Set Supported account types to Single tenant only.
-
Click Register. The Knox E-FOTA application is created. The client ID and tenant ID are displayed.
-
Copy the values next to Application (client) ID and the Directory (tenant ID).
Step 2: Create a client secret
-
In the left navigation, click Certificates & secrets.
-
In the main screen, under Client secrets, click New client secret.
-
Under Add a client secret, do the following:
-
Enter a description for the client secret, for example, Client secret for Knox E-FOTA.
-
Under Expires, select 24 months.
-
Click Add. The new client secret is added under Client secrets.
-
-
Copy the value of your new client secret.
Step 3: Add permissions to your Knox E-FOTA app in Microsoft Azure
-
In the left navigation, click API permissions.
-
In the main screen, under Configured permissions, click Add a permission.
-
Under Request API permissions, do the following:
-
Click Microsoft Graph.
-
Click Application permissions.
-
Under Select permissions, select all of the following permissions:
You can find these permissions by entering them in the search bar.
Device.Read.AllUser.Read.AllGroup.Read.AllGroupMember.Read.AllDeviceManagementManagedDevices.Read.All
-
Click Update permissions. The permissions are saved for the app you registered in step 1.
-
-
In the main screen, under Configured permissions, click Grant admin consent for.
-
Click Yes when prompted to confirm your request. The Status column of the Configured permissions table shows Granted for.
On this page
Is this page helpful?