Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Microsoft Intune device read checks. The legacy Intune catalog entry checks device/security read access. Use the separate Microsoft Defender incident guide for the new company-scoped incident-to-ticket workflow. Current availability: Authorization check only — ingestion pending. Before you start. A dedicated, read-only organization-owned API identity with the vendor’s required permissions. Step 1. Register a dedicated Entra application for read-only device/security access. Step 2. Grant DeviceManagementManagedDevices.Read.All, SecurityIncident.Read.All and SecurityAlert.Read.All application permissions with tenant administrator approval. Step 3. Save the dedicated INTUNE_TENANT_ID, INTUNE_CLIENT_ID and INTUNE_CLIENT_SECRET in protected configuration. Step 4. Run the managed-device read check. Automatic Intune device import remains unimplemented in this legacy entry. For Defender incidents, open Companies > company > Security and follow the Microsoft Defender incident connector article. Now verify the result. The provider read check succeeds with only the intended tenant’s records. The UI reports authorization-only status and does not claim completed synchronization. If you get stuck. A 403 usually needs a permission, license or administrator-consent correction. Do not grant broad write permissions to make a read-only check pass. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.