Privacy & security
What IntuneAssistant can access, what it keeps and how you take access away again.
It only reads
Every request IntuneAssistant makes to look at your tenant is a read request. It does not create, change or delete anything. It works in your own user context, so you only see what your roles allow you to see, and every request appears in the audit logs under your name.
Permissions
These Microsoft Graph permissions are approved when you connect your tenant.
| Permission | Used for |
|---|---|
DeviceManagementConfiguration.Read.All | Read Intune configuration profiles and baselines |
DeviceManagementApps.Read.All | Read managed applications |
DeviceManagementServiceConfig.Read.All | Read device management service configuration |
DeviceManagementScripts.Read.All | Read management scripts |
Group.Read.All | Read groups and their members |
User.ReadBasic.All | Read basic user profiles |
Policy.Read.ConditionalAccess | Read Conditional Access policies |
Directory.AccessAsUser.All | Directory lookups, such as roles and groups, on behalf of the signed-in user |
Your data
| What | Kept? | Why |
|---|---|---|
| Your account name, tenant ID and tenant domain | Yes | To recognize you and show which tenant you connected |
| Tenant data (policies, devices, assignments) | No | Read on request, shown in your browser and not stored |
| Sign-in tokens | No | Short-lived and only held in your browser session |
Taking access away
You stay in control.
Open Microsoft Entra ID, go to Enterprise applications, find the IntuneAssistant application and delete it. Access stops immediately.