Assigned-To User Synchronization for InTune

Connector Applicability

Applies to Source Connectors

InTune

Applies to Destination Connectors

All

Assumptions

These instructions assume you have already setup a source connection in CI Sync for InTune using the CI Sync instructions here: Add InTune to SaaS Agent.

Pre-Read

Syncfish recommend customers read the following documentation before changing the Connection Setting/s described below.

  1. Understanding the use of CI Sync Connection Settings

  2. Rule 9 - Synchronization of Assigned to User attribute for InTune

Locating and Amending the Connection Setting in the CI Sync UI

  1. Navigate to the Settings page

  2. Under the Source Connections heading (list), locate your InTune connection.

  3. Click the Update link on the right hand side of the InTune connection.

  4. Scroll down and locate the Section Heading and view the Individual Settings.

User synchronization 2.jpg

The screen shot is provided only as sample to assist when reading this page. The state of your own CI Sync UI will depend on whether you are starting from the CI Sync default position or if you have already amended one/more of the settings.

  1. Tick the Override default box/boxes and then use the sliders related to the individual settings. The following table elaborates any further information about these particular settings.

Setting

Type

Additional Notes

Enable Assigned To User Synchronization

Slider

When enabled:

  1. CI Sync will begin to read a config driven attribute from the source system (in this case from InTune).

  2. The CI Sync UI will expose two additional settings as explained in the next two rows (these are the config drive attributes).

For a diagrammatic view of how Assigned To user synchronization works in CI Sync (covering both the source system behaviour/settings and the destination system behaviour settings), please read the Addition Information section on this InTune Default Config Guide page:

Rule 9 - Synchronization of Assigned to User attribute for InTune | Additional Information

Important PII Consideration when enabling this setting

When enabling this setting the CI Sync UI will warn of potential PII implications. Please read the message shown and also read Section 7 (Overview of data used within the Service) in the CI Sync Service Specification published here. Section 7 explains the impact of enabling this setting for both persisted data and transited data.

Source field

Choicelist

The Source Field provides for the selection of the specific Intune Primary User attribute that will be used to identify the user against the related ServiceNow sys_user attribute which is defined in the subsequent setting (see next row below).

The choices for this setting are:

  • Email Address

  • User Principal Name

ServiceNow correlation field

Choicelist

The ServiceNow correlation field defines which field in the ServiceNow sys_user table will be used to lookup the value read from the InTune source field as defined on the prior setting (see above row).

The choices for this setting are:

  • email

  • User ID

  • Name

  • Custom

Important Note if using “Custom” for this setting

If you select “Custom” as the sys_user correlation setting, you must also define the specific custom field in question using a CI Sync Connection Setting on your ServiceNow Destination Connection.

Read this Connection Setting for more information:

Define a Custom Field name when using User Synchronization from a Source System


  1. After modifying the settings, scroll to the bottom of the page, tick the “I consent…” checkbox and finally click the Save connection button.

  2. You can now run a sync job and the amended settings will be applied causing the CI Sync Data Sync rules to be modified accordingly.

Importantly

Make sure you consciously override the setting against either your TEST or PROD environment (i.e. your TEST vs PROD sync jobs).

For more information on how to use TEST vs PROD Connection Settings please read Understanding the use of CI Sync Connection Settings.

Syncfish strongly recommend making changes for TEST environment/sync jobs first. Only modify PROD related settings after thoroughly validating the intended results in TEST.