What syncs automatically
- Entra ID users → AssetTrack employees (matched by email address, then user principal name)
- Intune-managed devices → asset register (matched by hardware serial number)
- Microsoft 365 & Entra licence SKUs → licence catalogue with human-readable names
- Per-user licence assignments → who has which seat, refreshed every 6 hours
- Device compliance state, last check-in, primary user, OS version and enrolment date
- Group memberships from Entra ID → available as filters and audience segments in AssetTrack
- Autopilot deployment profile assignments (where present) → tied back to the asset record
Ten-minute setup — no agent on your endpoints
Create an app registration in Entra ID, grant three read-only Microsoft Graph permissions (User.Read.All, Device.Read.All, Organization.Read.All), and paste the Tenant ID, Application (Client) ID and a Client Secret into AssetTrack. The first sync starts within a minute; subsequent syncs run every six hours and can be triggered on demand from the integration page.
The integration is entirely read-only — AssetTrack never modifies your tenant, disables accounts, wipes devices, or writes back to Graph. If you disconnect, your data stays and the sync simply stops. Client secrets are stored encrypted at rest and never returned to the browser.
Serial-first matching keeps your register clean
Intune reports the hardware serial for every device. AssetTrack matches on serial first, so a laptop already in your register (from a purchase order, network discovery, or CSV import) is updated in place — not duplicated. Devices Intune sees but AssetTrack doesn't land in the discovery queue for one-click enrolment, with the pre-populated make, model, serial, primary user and warranty end where Intune knows it.
The same match pipeline covers Entra ID users: existing employees are updated by email, new hires appear as discoveries. Leavers detected by an Entra sign-in-blocked state are surfaced in the offboarding view so IT can reclaim their kit and revoke their licences before the next payroll run.
See where Microsoft money is being spent
Every licence SKU is decoded into a friendly name: Microsoft 365 E3, Business Premium, Copilot for Microsoft 365, Power BI Pro, Entra ID P2, Intune Plan 1, Exchange Online Plan 2, and dozens more. The licence view shows total seats, assigned seats, unassigned seats you're paying for, cost per seat, and every employee holding a seat.
Combined with last-sign-in data from Entra, you can spot the R390/month E5 assigned to someone who left three months ago, the Copilot seat nobody activated, and the Power BI Pro count that quietly grew from 12 to 47. Export any of it to CSV for finance, or trigger an internal review workflow from within AssetTrack.
Compliance and device-posture reporting
Intune's compliance state (compliant, non-compliant, in grace period, error) flows into AssetTrack alongside the asset's own status. That means you can answer 'which finance-team laptops are non-compliant AND out of warranty AND due for refresh in Q3?' in a single filter — the sort of cross-cutting report that usually needs a spreadsheet and a Friday afternoon.
For MSPs, the same view scoped per customer tenant becomes a monthly compliance report you can send from AssetTrack without opening the Intune console.
Multi-tenant and MSP-friendly
Each AssetTrack organisation connects to its own Microsoft 365 tenant. MSPs manage one customer per tenant, with one AssetTrack login switching between them — no shared admin accounts, no browser profile juggling, no CSP delegated permissions to negotiate.
Where a customer already runs Lighthouse or Partner Center, AssetTrack sits alongside as the asset and licence system of record, complementing the operational tooling rather than replacing it.
What we DON'T do (on purpose)
- We don't request Mail, Files, Calendars, Sites, or Chat permissions — ever
- We don't write back to Entra or Intune, so we can't disable accounts, remove licences, or wipe devices
- We don't need Global Admin day-to-day — admin consent is a one-off during setup
- We don't copy your directory into a third-party CRM or resell any of the data
- We don't need on-prem AD Connect or ADFS — Entra alone is enough