Can AI agents automate Microsoft Intune?
Microsoft · saas · endpoint-managemententerprise
Microsoft Intune is unusually API-complete for a cloud administration product. Microsoft states that every action in its web admin center is backed by Microsoft Graph. The public v1.0 and beta resources cover device inventory and compliance, configuration and security policies, application deployment and protection, enrollment, role-based access control, audit and reporting, and high-impact remote actions such as passcode reset, retire, and wipe. Graph supports delegated OAuth access and unattended app-only access. Both require explicit permissions; application permissions require tenant administrator consent, and Intune RBAC, scope tags, licensing, and endpoint-specific availability remain additional gates. Microsoft Graph SDKs cover seven programming environments, and the cross-platform Graph PowerShell SDK exposes the generated API surface as cmdlets with structured objects, making it the strongest command path. Production automation must isolate read-only inventory from device-impacting writes, pin v1.0 where possible, and treat beta resources as unstable. A current Intune-specific first-party MCP server, Intune change-notification coverage, and repeatable computer-use viability were not established in this pass.
Best path today: api · Overall automatability: 9/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restoauth2-delegatedoauth2-app-only coverage: full · docs |
| SDK | yes | csharpgojavajavascriptphppowershellpython official: yes |
| MCP | unknown | verdict: unknown |
| Integrations | unknown | |
| CLI | yes | |
| Extensibility | yes | microsoft-graphgraph-powershellgraph-sdks webhooks: unknown |
| Data access | export: api-json, powershell-objects · import: api-json, powershell-objects | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. Microsoft states that every Intune admin-center action is backed by Microsoft Graph, and the Graph SDKs and PowerShell modules provide supported automation without browser control. |
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 9 | — | — | 8 | — | — | 9 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-08-16 |
platforms | declared | source | 2026-08-16 |
license | declared | source | 2026-08-16 |
modalities.api.exists | declared | source | 2026-08-16 |
modalities.api.kinds[0] | declared | source | 2026-08-16 |
modalities.api.auth[0] | declared | source | 2026-08-16 |
modalities.api.auth[1] | declared | source | 2026-08-16 |
modalities.api.coverage | declared | source | 2026-08-16 |
modalities.sdk | declared | source | 2026-08-16 |
modalities.sdk.languages | declared | source | 2026-08-16 |
modalities.cli.exists | declared | source | 2026-08-16 |
modalities.extensibility.scripting | declared | source | 2026-08-16 |
modalities.data_access.export | declared | source | 2026-08-16 |
modalities.data_access.import | declared | source | 2026-08-16 |
verdict.scores.api | declared | source | 2026-08-16 |
verdict.scores.cli | declared | source | 2026-08-16 |
freshness.watch[0].url | declared | source | 2026-08-16 |
freshness.watch[1].url | declared | source | 2026-08-16 |
freshness.watch[2].url | declared | source | 2026-08-16 |
Last verified 2026-08-16 · volatility high · JSON record