Integrating Microsoft Entra ID with LDO
- Navigate to the Microsoft Azure Portal.
- Proceed to Microsoft Entra ID > App registrations and select New registration.
- Register a new application. Securely note the following generated values:
- Application (client) ID
- Directory (tenant) ID
- Generate a Client Secret for authentication.
- Configure a Redirect URI (platform: Web) as provided by Lenovo.
- Grant the necessary Microsoft Graph API permissions (e.g., DeviceManagementManagedDevices.ReadWrite.All, DeviceManagementServiceConfig.ReadWrite.All) to the application and grant admin consent.
- In the LDO console, navigate to Policy Management > Feature Settings > Connectors.
- Locate and select Manage Connector for Microsoft Intune.
- In the configuration pane, enter the following credentials:
- Directory ID (Tenant ID)
- Application ID (Client ID)
- Client Secret
- Select Connect to establish the integration.
Synchronize Microsoft Intune Groups
- From either Policy Management or Device Management in LDO, select the option to Sync Intune Groups.
- A list of available groups from Intune will be displayed (up to 100 groups).
- Select the desired groups and initiate synchronization.
This process creates the group structure within LDO but does not synchronize individual member details.
- Ensure the Company Portal app is installed on the target Windows devices.
- Instruct users to sign into the Company Portal with their corporate credentials and complete the enrollment process.
- Verify that the devices appear as successfully enrolled in the Microsoft Intune admin center. Please allow up to 30 minutes for the enrollment status to propagate.
Deploy the Lenovo UDC Provisioning Pack via Intune
- Within the Lenovo Device Orchestration portal, download the UDC provisioning pack (organization-setup.intunewin).
- In the Microsoft Intune admin center, add a new Windows app of the Win32 type.
- Upload the organization-setup.intunewin file.
- Configure the installation settings:
- Install command: install.cmd
- Uninstall command: uninstall.cmd
- Configure the detection rules to ensure accurate installation reporting. Assign the application to the required device groups.
Onboard Devices to Lenovo Device Orchestration
- In the Lenovo Device Orchestration portal, navigate to the device onboarding section.
- Enter the App ID from the relevant Intune application deployment.
- Select the target devices for onboarding.
- The device status will initially appear as Pending. Once the UDC provisioning pack is successfully installed and registers with the LDO service, the status will change to Onboarded.

- Provisioning Pack Validity: The generated Lenovo UDC provisioning pack is currently valid for 24 hours. This duration is subject to change in future releases.
- Synchronization Timing: Synchronization of data between Microsoft Intune and Lenovo Device Orchestration typically occurs within 10 to 30 minutes. In larger environments, this process may take longer.
- Pre-claimed Devices: Devices that were already claimed directly in Lenovo Device Orchestration prior to their enrollment in Microsoft Intune may not onboard successfully through this process. It is recommended to use a unified enrollment path.
Related Articles
Configuring Entra ID for LDO SSO
This guide explains how to migrate Lenovo Device Orchestration (LDO) to Microsoft Entra ID. This process involves setting up a new app in Microsoft Entra, collecting necessary configuration data, and updating the authentication settings in LDO. ...
Migrating LDO to Microsoft Entra
This guide explains how to migrate Lenovo Device Orchestration (LDO) to Microsoft Entra ID. This process involves setting up a new app in Microsoft Entra, collecting necessary configuration data, and updating the authentication settings in LDO. ...
LDO DEX (SysTrack)
Lenovo Device Orchestration can be bundled with various Digital Experience Management (DEX) solutions. Currently, LDO supports integration with SysTrack by Lakeside Software. Integrations with SysTrack The LDO DEX (SysTrack) bundled solution includes ...
Deploying Lenovo Device Orchestration Agent in Intune
This article provides instructions for creating an Intune application to deploy the Lenovo Device Orchestration Agent. Download the LDO Agent and set the expiry date of the agent. In the LDO console, go to Device Management > Devices. Click on the ...
Setting Up LDO ServiceNow Integration
Prerequisites Before configuring the integration between LDO and ServiceNow, ensure the following prerequisites are met to establish proper synchronization: Terminology Alignment In LDO, a physical device (such as a laptop, desktop, or server) is ...