Privacy & security

What IntuneAssistant can access, what it keeps and how you take access away again.

It only reads

Every request IntuneAssistant makes to look at your tenant is a read request. It does not create, change or delete anything. It works in your own user context, so you only see what your roles allow you to see, and every request appears in the audit logs under your name.

Permissions

These Microsoft Graph permissions are approved when you connect your tenant.

PermissionUsed for
DeviceManagementConfiguration.Read.AllRead Intune configuration profiles and baselines
DeviceManagementApps.Read.AllRead managed applications
DeviceManagementServiceConfig.Read.AllRead device management service configuration
DeviceManagementScripts.Read.AllRead management scripts
Group.Read.AllRead groups and their members
User.ReadBasic.AllRead basic user profiles
Policy.Read.ConditionalAccessRead Conditional Access policies
Directory.AccessAsUser.AllDirectory lookups, such as roles and groups, on behalf of the signed-in user

Your data

WhatKept?Why
Your account name, tenant ID and tenant domainYesTo recognize you and show which tenant you connected
Tenant data (policies, devices, assignments)NoRead on request, shown in your browser and not stored
Sign-in tokensNoShort-lived and only held in your browser session
Taking access away
You stay in control.
Open Microsoft Entra ID, go to Enterprise applications, find the IntuneAssistant application and delete it. Access stops immediately.