Skip to main content
NewThird-party apps blocked in your tenant? Run it locally

Audit-ready Intune documentation, straight from your tenant.

Export policies, settings, and assignments to PDF or Word, then map your configuration to compliance frameworks like ISO 27001, NIST, and Essential Eight. Free in the browser, or on your own machine with the desktop app.

Free, delegated, read-only access. The first sign-in in your tenant needs a one-time approval from a Global Administrator, Privileged Role Administrator, or Cloud Application Administrator. /

Can't sign in to third-party apps with your work account?

Run the desktop app instead. It connects through an app registration you create in your own Microsoft tenant, so we never get access to it, and tenant data stays on your computer. Windows and macOS, 30-day money-back guarantee.

See desktop plans
Reports exported
8,387
Organizations
1,402
Active users this month
250
Cover page of a sample Intune documentation reportExecutive summary page with key metrics, assignment coverage, and potential gaps

Real export from a sample tenant

How it works

From tenant to finished report in three steps.

  1. Step 1

    Sign in with Microsoft

    Use your work account. An admin approves the read-only permissions once per tenant; after that, anyone with Intune read access can sign in.

  2. Step 2

    Collect and select

    Sections stream in with live progress. Pick configurations by type, search, or select everything; assignments and filters come along.

  3. Step 3

    Export or map to a framework

    Download a branded PDF or Word document, or generate a compliance evidence report. Sensitive values stay redacted.

What you get

A report a reviewer can actually read.

Every setting with its value and description, grouped by policy, with an executive summary that surfaces unassigned and stale configurations.

  • Broad Intune coverage

    Core policies plus 35 additional Graph resource collections: apps, updates, enrollment, RBAC, tenant settings, connectors, and more.

  • Assignments resolved

    Group targets and filters shown by name, with optional device counts by platform.

  • Your branding

    Company logo, colors, headers, footers, and confidentiality notices on every page.

  • PDF and Word

    Polished documents ready for audits, handovers, and change records.

  • Honest collection status

    Partial or failed Graph collections are flagged with endpoint, status, and a permission hint instead of looking empty.

  • Secrets redacted

    Script bodies, passwords, tokens, and payloads are replaced with [Redacted] before display or export.

Download the full sample report (PDF)
Executive summary page of the sample reportSettings Catalog page listing each setting with its value and description

Compliance evidence

Turn your configuration into audit evidence.

When an auditor, insurer, or customer questionnaire asks you to prove encryption, screen lock, and patching, map your tenant to the framework they reference instead of collecting screenshots.

  • Each mapped requirement cites the policy, setting, value, and assignment used as evidence.
  • Counter-evidence is surfaced, not hidden.
  • Requirements Intune cannot prove stay explicitly unassessed.
How compliance mapping works

Supported frameworks

  • ISO/IEC 27001:2022
  • SOC 2
  • NIST SP 800-53
  • NIST SP 800-171
  • NIST CSF 2.0
  • BSI IT-Grundschutz
  • Def Stan 05-138
  • Cyber Essentials
  • ASD Essential Eight

Reports are supporting evidence for an assessment, not a certification or a calculated maturity level.

Security

Read-only access. No stored tenant data.

Graph responses pass through our application server only to be collected, normalized, and redacted. Your configuration, access token, and generated documents are never persisted.

  • Delegated, read-only permissions

    Microsoft Graph scopes that can read your Intune configuration, never change it. No app-only permissions.

  • Sensitive values redacted

    Script bodies, passwords, tokens, payloads, QR codes, and configuration-file contents are removed before dashboard display or export.

  • Reports generated in your browser

    PDF and Word documents are built on your device and never uploaded to us.

  • Revoke access anytime

    Delete the Intune Documentation app from Entra ID enterprise applications to remove consent for your tenant. Signing out only ends your session.

How your data flows

  1. Microsoft Graph API

    Your Intune tenant, delegated read-only access

  2. Transient application processing

    Collects, normalizes, and redacts responses without persistent tenant storage

  3. Your browser

    Shows collected sections and builds the report locally

  4. Your PDF or Word file

    Saved directly to your device

Intune configuration storageNot used

For your security review

Getting the desktop app approved internally?

The app connects through an app registration you create in your own Microsoft tenant, so we never get access to it. Share the one-page security and architecture overview with your security team: it covers every read-only Graph permission and each connection the app makes, including what our licensing service receives.

Download PDF

Ways to run it

Hosted, self-hosted, or on your desktop

The same documentation engine in every edition. Pick the one that fits where your tenant data is allowed to go.

Web

Free

The fastest start. Nothing to install or operate.

  • Runs at intunedocumentation.com
  • Always on the latest version
  • No tenant data stored

Self-hosted

Free

Open source under the Elastic License 2.0.

  • One docker compose command
  • Your own Entra app registration
  • Telemetry disabled by default

Desktop app

From €99/mo

For data that must stay on your machines, and for MSPs with many tenants.

  • Collects straight from Graph on your device
  • Configuration, tokens, and exports never leave your machine
  • Multi-tenant plans for MSPs
  • Your own Entra app registration

Questions, answered

Frequently asked questions

Do I need admin rights to use it?

The first time anyone in your organization signs in, Microsoft asks for tenant-wide admin consent, because the Intune and group read permissions are admin-consent scopes. It can be approved by a Global Administrator, Privileged Role Administrator, or Cloud Application Administrator. After that, anyone with read access to Intune can sign in and generate reports, unless your tenant requires user assignment for the app, in which case only assigned users can. What they see is limited by their own Intune role.

Is my Intune data secure?

We use Microsoft OAuth 2.0 with delegated, read-only access. The application server processes Graph responses transiently to collect, normalize, and redact sensitive values, but it does not persist your tenant configuration or access token. PDF and DOCX generation happens in your browser, and generated documents are not uploaded or stored by us.

Is the Intune Documentation tool really free?

Yes. The web tool is free with no usage limits and no credit card. A separate, paid desktop app is available for teams that want collection to run entirely on their own machines and for MSPs that document many tenants. It starts at €99 per month with a 30-day money-back guarantee.

Why does Defender flag 'Suspicious application consent for offline access'?

This is a common alert when an app requests the standard 'offline_access' permission from Microsoft identity (used to refresh tokens without repeatedly prompting you). It does NOT grant extra data access beyond your approved read-only scopes, and we use only delegated permissions (no application permissions). Tokens are cached in your browser session and are never stored on our server, and we do not store tenant data.

What Intune policies can I export?

Coverage includes device configurations, Settings Catalog, compliance, security baselines, administrative templates, scripts and remediations, app protection and configuration, managed apps, Windows updates, enrollment and Autopilot, assignment filters, RBAC, tenant and service settings, connectors, and specialist policies. Conditional Access is optional and requested separately with Policy.Read.All.

Which compliance frameworks are supported?

Compliance reports map your Intune configuration to ISO/IEC 27001:2022, SOC 2, NIST SP 800-53, NIST SP 800-171, NIST CSF 2.0, BSI IT-Grundschutz, Def Stan 05-138, Cyber Essentials, ASD Essential Eight. Each mapped requirement cites the policy names, settings, values, and assignments used as evidence. Requirements that Intune configuration cannot prove stay explicitly unassessed, so the report is supporting evidence, not a certification.

Are secrets or script bodies included in the report?

No. Sensitive values such as script bodies, passwords, tokens, pre-shared keys, QR-code payloads, encoded configuration files, and large app icons are replaced with [Redacted] before data reaches the dashboard or an export. The report retains useful metadata so reviewers can still identify the resource.

Can I customize the Intune PDF report?

Yes, you can customize your documentation with branding options including company logo, custom colors, headers, footers, and confidentiality notices. You can also select specific configurations to include or exclude from the report.

Can I self-host Intune Documentation?

Yes. Intune Documentation is open source under the Elastic License 2.0. The source is at https://github.com/ugurkocde/IntuneDocumentation and you can self-host it with a single docker compose command and your own Microsoft Entra app registration. Telemetry is disabled by default, and Graph responses are only processed by your own deployment.

What happens if Microsoft Graph cannot return a collection?

The dashboard keeps any successfully collected sections and clearly marks partial or failed collections. Warnings include the affected section, endpoint, status code, and a permission hint when available, so a failed request is not presented as a confirmed empty result.

Why does the tool use Microsoft Graph beta endpoints?

A number of Intune administration resources needed for complete documentation are currently exposed through Microsoft Graph beta. The tool uses those endpoints only for delegated, read-only collection and isolates failures by resource so one unavailable endpoint does not hide the rest of the report.

How long does it take to generate Intune documentation?

Collection time depends on tenant size, Graph throttling, and the resources available in your environment. The dashboard streams sections as they finish and shows live progress, then lets you export the successfully collected data even when another section reports a warning.

What is the Intune Documentation Generator?

The Intune Documentation Generator is a free, read-only tool that collects your Microsoft Intune configuration through Microsoft Graph and turns it into a PDF or Word report. It covers the original policy areas plus 35 additional resource collections across updates, scripts and remediations, enrollment and provisioning, apps, assignments and RBAC, tenant settings, connectors, and specialist policies. The exact resources returned depend on your tenant, licensing, and permissions.

Try it now

Ready to stop documenting Intune by hand?

Sign in with Microsoft and export your first report in minutes. Free, read-only, and nothing stored.

How sign-in and security work

You sign in with Microsoft; authentication is handled by Entra ID using OAuth 2.0/OpenID Connect. We never see your password and only request read-only, delegated permissions.

Required permissions and why

We request a small set of delegated, read-only Microsoft Graph scopes to read your Intune configuration and build your report. No app-only permissions. Scopes marked as admin consent are approved once per tenant by a Global Administrator, Privileged Role Administrator, or Cloud Application Administrator.

User.Read
Basic profile and sign-in; required by the Microsoft identity platform.
Delegated, user consent
DeviceManagementConfiguration.Read.All
Read Intune device configuration policies and settings.
Delegated, read-only, admin consent
DeviceManagementApps.Read.All
Read app configuration and app protection policies.
Delegated, read-only, admin consent
DeviceManagementManagedDevices.Read.All
Read managed device inventory for counts by platform.
Delegated, read-only, admin consent
DeviceManagementRBAC.Read.All
Read Intune RBAC roles and assignments if referenced.
Delegated, read-only, admin consent
DeviceManagementServiceConfig.Read.All
Read Intune service configuration information.
Delegated, read-only, admin consent
DeviceManagementScripts.Read.All
Read script and remediation metadata. Script bodies are redacted before display or export.
Delegated, read-only, admin consent
Group.Read.All
Resolve Entra group names in policy assignments.
Delegated, read-only, admin consent
Policy.Read.All
Read Conditional Access policies to include in the report.
Optional; requested separately for Conditional Access. Delegated, read-only, admin consent