Configuring Microsoft Intune Connector
I. Generate Client Secret and Apply Permissions
- Sign in to Microsoft Azure Portal.
- Go to Microsoft Entra ID > App registrations and select New registration.
- Register a new application, and securely note the following generated values:
- Application (client) ID
- Directory (tenant) ID
- Generate a Client Secret for authentication.
- Configure a Redirect URI (platform: Web) as provided by Lenovo.
- Grant the following Microsoft Graph API permissions to the application:
- DeviceManagementManagedDevices.Read.All
- DeviceManagementApps.ReadWrite.All
- Group.ReadWrite.All
- Directory.Read.All
- These permissions are required to:
- Create an Intune group (“CommonAgentGroup”)
- Link the UDC provisioning package to the group
- Link devices claimed through Intune to LDO
- Grant admin consent to apply permissions.
- In the LDO console, go to Configuration & Settings > Organization Settings > Organization Account > Connectors.
- Under Microsoft Intune, click Add Connection.
- Enter the following credentials:
- Directory ID (Tenant ID)
- Application ID (Client ID)
- Client Secret
- Select Connect to establish the integration.
- LDO displays the permissions required for device onboarding. Any missing permissions appear in red. If a permission is missing, return to Microsoft Entra ID and add it before proceeding.
- Click Next.
- Select the Intune groups to synchronize, or click Select all groups.
- Click Sync.
- Click Close.
After synchronization is complete, the connector status changes to Active.
Group synchronization creates the group structure within LDO but does not synchronize individual group members.
- Ensure the Company Portal app is installed on the target Windows devices.
- Instruct users to sign in to the Company Portal with their corporate credentials and complete the enrollment process.
- Verify that the devices appear as successfully enrolled in the Microsoft Intune Admin Center. Allow up to 30 minutes for the enrollment status to propagate.
IV. Deploy the Lenovo UDC Provisioning Pack via Intune
- In the Lenovo Device Orchestration portal, download the UDC provisioning pack (organization-setup.intunewin).
- In the Microsoft Intune admin center, add a new Windows app of the Win32 type.
- Upload the organization-setup.intunewin file.
- Configure the installation settings:
- Install command: udc_setup.exe /VERYSILENT /NORESTART
- Uninstall command: C:\Windows\System32\drivers\Lenovo\udc\Data\InfBackup\UDCInfInstaller.exe -uninstall
- Configure the detection rules and assign the application to the required device groups.
V. Onboard Devices to Lenovo Device Orchestration
- In the Lenovo Device Orchestration portal, go to the device onboarding section.
- Enter the App ID from the relevant Intune application deployment.
- Select the target devices for onboarding.
- The device status will initially appear as Pending. After the UDC provisioning pack is successfully installed and registered with the LDO service, the status changes to Onboarded.
- Synchronization timing: Synchronization between Microsoft Intune and Lenovo Device Orchestration typically completes within 10–30 minutes. Large environments may require additional time.
- Pre-claimed devices: Devices that were previously claimed directly in Lenovo Device Orchestration before enrollment in Microsoft Intune might not onboard successfully through this workflow. Use a single onboarding method whenever possible.
Related Articles
Configuring Entra ID for LDO SSO
This guide explains how to migrate Lenovo Device Orchestration (LDO) to Microsoft Entra ID. This process involves setting up a new app in Microsoft Entra, collecting necessary configuration data, and updating the authentication settings in LDO. ...
Configuring SentinelOne Connector
This article explains how to configure the SentinelOne connector in Lenovo Device Orchestration (LDO). Once configured, the integration enables ThinkShield Firmware Assurance (TSFA) to send security posture change events to SentinelOne, improving ...
Setting Up Organization Accounts
Accessing Your Account When your organization's portal is created, a single administrative account will be created. The IT Owner (Org Admin) specified to Lenovo at the time of sale will receive a Lenovo Device Orchestration (LDO) e-mail indicating ...
Onboarding Windows Devices
Device Management supports an automated process that simplifies the onboarding of Windows devices. Users can easily download the .zip file package with the necessary files and apply to the devices. Any Lenovo Windows device can be automatically added ...
Configuring Google Workspace Integration
This article explains how to configure Google Workspace for ChromeOS within Lenovo Device Orchestration (LDO). This setup enables LDO to securely connect with your organization’s Google Cloud environment and retrieve ChromeOS device data for ...