Skip to content

Set Up Intune Permissions for CustomApps Upload

To upload a CapaOne Company App to Intune, the Entra ID application that CapaOne uses needs Intune permissions in Microsoft Graph. This guide shows you how to add them.

  1. Log in to the Azure portal

  2. Navigate to App registrations

    • In the left menu, select Microsoft Entra ID.
    • Click App registrations.
  3. Select the application

    • Open the app registration that your CapaOne Entra ID integration uses.
    • If you create a new app registration instead, also create an Entra ID integration for it in CapaOne.

App registrations page with an existing app or the New registration button

  1. Configure API permissions

    • In your app registration, go to Manage > API permissions
    • Click Add a permission

App registration API permissions page with the Add a permission button

  1. Add the required Intune permissions

    • Select Microsoft Graph

    • Choose Application permissions

    • Search for and add the following permissions:

      • Organization.Read.All
      • DeviceManagementApps.ReadWrite.All
      • DeviceManagementConfiguration.ReadWrite.All
      • DeviceManagementServiceConfig.ReadWrite.All

Microsoft Graph application permissions selected for Intune

  1. Grant admin consent

    • After adding permissions, click Grant admin consent for your organization.

API permissions list after granting admin consent

  1. Verify the permissions

    • Ensure the permissions are listed and show as “Granted for [Your Organization]”

Granted Intune permissions listed for the organization

CapaOne checks the permissions when you upload. If a permission is missing, the upload fails with a message that starts with Missing required permission: followed by the name of the permission, for example DeviceManagementApps.ReadWrite.All. Add the permission, grant admin consent, and upload again. This message also appears if the tenant has no active Intune subscription.