Home › Setup guides › Connect Decolla to your Microsoft Intune tenant (admin consent)
Setup guide · from scratch
Connect Decolla to your Microsoft Intune tenant (admin consent)
Connecting your tenant grants Decolla delegated Microsoft Graph permission to drive Intune on your organisation's behalf — a one-time job that must be done by a Global Administrator. The classic trap: your browser silently reuses an existing Microsoft session, so you sign in and consent in the wrong tenant. Always start from a clean or private browser window.
Decolla cockpit + Microsoft admin consent (login.microsoftonline.com)assisted guide — Decolla walks you through this
≈ 10 min
Start here — Microsoft foundation · step 3 of 3 · ≈ 10 min‹ Previous
Do these first — this guide assumes you already have:
You sign in as a Global Administrator (or Privileged Role Administrator) of the Microsoft Entra tenant that owns the devices — only these roles can consent on behalf of the whole organisation
The tenant has an active Microsoft Intune subscription and Intune is provisioned
You have a Decolla cockpit account with rights to add a tenant connection
You know which tenant you are connecting — its domain (e.g. contoso.onmicrosoft.com) or tenant ID
The Decolla way — skip the clicks.
Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.
⏱ By hand: about 10 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
Step 1. In the Decolla cockpit, open the tenant connections area (typically under Settings, Integrations, or Connections) and start the action that connects your Microsoft Intune tenant.
Screenshot: The cockpit's connections/integrations screen showing the Microsoft Intune tenant card with a Connect (or equivalent) button, status reading 'Not connected'. (captured during a live customer build — coming to this page)
Why: This begins the OAuth admin-consent hand-off from Decolla to Microsoft. Nothing is granted in your tenant yet — you are only launching the sign-in.
Watch for: Exact cockpit labels vary by version. The wording used here ('Connect Microsoft Intune tenant', 'Integrations', 'Connections') is indicative, not guaranteed — confirm the real labels in your cockpit before following any screenshot literally.
Step 2. Open the Microsoft sign-in in a clean browser session: a private/incognito window, or sign out of every other Microsoft account first.
Screenshot: A fresh InPrivate/Incognito browser window with no Microsoft account already signed in. (captured during a live customer build — coming to this page)
Why: Admin consent is granted to whichever tenant the signed-in account belongs to. A reused browser session is the single most common way to consent in the wrong tenant.
Don’t: Don't proceed while signed in as your everyday or personal Microsoft account 'just to see' — if that account is an admin somewhere else, you can grant consent in the wrong tenant.
Step 3. When Microsoft's sign-in page (login.microsoftonline.com) opens, sign in as a Global Administrator of the tenant that owns the devices you want Decolla to manage.
Screenshot: The Microsoft sign-in page at login.microsoftonline.com with the Global Administrator account's email entered. (captured during a live customer build — coming to this page)
Why: Consenting on behalf of the whole organisation requires a Privileged Role Administrator or Global Administrator (a Cloud Application Administrator can consent to everything except Microsoft Graph application roles). A standard user cannot.
Watch for: If you land on a 'Need admin approval' or 'Approval required' screen, your account isn't permitted to consent. Hand this step to a Global Administrator rather than submitting a request that may sit unactioned.
Step 4. Complete multi-factor authentication if prompted.
Screenshot: The MFA prompt — authenticator approval, one-time code entry, or phone verification. (captured during a live customer build — coming to this page)
Watch for: Conditional Access can block the sign-in outright (untrusted location, non-compliant device). If it does, retry from a permitted network/device or have your identity admin add an exclusion — it is not a Decolla fault.
Step 5. On the consent screen, read the delegated Microsoft Graph permissions Decolla is requesting — the Microsoft Intune device-management ones (entries such as 'Read and write Microsoft Intune configuration', 'Read Microsoft Intune devices', and 'Read and write Microsoft Intune device configuration and policies'), plus the basic 'Sign in and read your profile' and 'Maintain access to data you have given it access to'.
Screenshot: The Microsoft consent dialog listing the requested permissions, with the requesting app shown as Decolla (or its publisher) and the Intune/device-management scopes visible. (captured during a live customer build — coming to this page)
Why: This is your one clear view of exactly what Decolla will be able to do in your tenant. Granting consent is a sensitive operation — it lets the app act against Intune on your organisation's behalf, so review it deliberately.
Watch for: The exact scope list is whatever Decolla's app registration requests and may differ from these examples. If you see anything unrelated to Intune device management - mailbox or SharePoint access, or directory-role management - stop and query it before consenting.
Step 6. If a 'Consent on behalf of your organisation' checkbox is shown, tick it, then select Accept.
Screenshot: The consent dialog with the 'Consent on behalf of your organisation' box ticked and the Accept button highlighted. (captured during a live customer build — coming to this page)
Why: Consenting tenant-wide (via the checkbox, or via Decolla's admin-consent link) grants the permissions for the whole organisation so individual admins using Decolla are never prompted to consent again.
Watch for: Depending on how Decolla launches the flow you may instead see a direct 'Accept' with no checkbox — that path is already tenant-wide and is fine. Note that granting tenant-wide consent can replace permissions previously granted tenant-wide for this same app.
Don’t: Don't accept a per-user grant when you meant to connect the whole tenant — a user-only consent covers just that one admin, so other admins would each be prompted to consent again.
Step 7. Let the browser redirect back to the Decolla cockpit — don't close the window while it is returning.
Screenshot: The browser navigating from login.microsoftonline.com back to the Decolla cockpit URL. (captured during a live customer build — coming to this page)
Why: The redirect carries the result of the consent back to Decolla and completes the registration. Closing early can leave the connection half-registered and force you to start again.
Step 8. In the cockpit's connections area, confirm the tenant now shows as connected, with its name or ID displayed.
Screenshot: The cockpit connections screen showing the Microsoft Intune tenant as 'Connected' (or a green status) with the tenant domain/ID. (captured during a live customer build — coming to this page)
Watch for: The exact status wording is cockpit-specific ('Connected', 'Active', a green light) — confirm which your version uses. If it still reads 'Not connected' after the redirect, the flow didn't complete; retry rather than assuming it worked.
Step 9. Verify the connection is genuinely usable: check that Decolla can read the tenant (a device count or tenant details populate), or run the cockpit's test/refresh action if one is offered.
Screenshot: The cockpit showing live tenant data — a device count or tenant details — or a successful 'test connection' result. (captured during a live customer build — coming to this page)
Why: A green 'Connected' badge only proves the consent was recorded. A successful read-back proves the Graph permissions are actually working end to end.
Watch for: If the badge is green but no data appears, the tenant may not have Intune provisioned/licensed, or you consented in a different tenant from the one holding your devices — recheck the tenant domain shown against the one you intended.