This article describes changes to the Microsoft Graph API permissions that the Nerdio Manager Intune integration requires.
As of July 31, 2025 the Graph API permission DeviceManagementScripts.Read/ReadWrite.All is required for Intune integration and you need to remove the existing DeviceManagementConfiguration.Read/ReadWrite.All permission. Failure to add the new permission will result in Intune script related tasks failing, including the deployment of UAM applications to Intune devices. This change is being implemented to enhance security and control over Intune management capabilities.
For more details, see Updates to required permissions for Microsoft Graph Beta API deviceManagement.
Note
This permission will be added automatically to 7.1 GA installs and later. Existing installations must be manually updated to reflect this change.
To resolve the issue
-
Navigate to System > Settings.
-
Do the following:
Select System > Settings > Integrations area. Navigate to the Intune section, select the down arrow to expand the section, and then select Configure.
-
In the Configure Intune dialog box, select Save.
The permissions are now updated.
Microsoft has changed the permission required for the Rotate LAPS password action. The action now requires the Graph API permission DeviceManagementManagedDevices.PrivilegedOperations.All. It previously required DeviceManagementManagedDevices.Read.All.
Nerdio Manager 8.2 and later requests the new permission. To apply the updated permissions to your Intune integration, follow the steps in To resolve the issue.
For the full list of permissions that each Intune management function requires, see Intune: Granular permissions.

Comments (1 comment)