Back

Create and authorise the FleetDM application on the Azure portal

To transition from Intune to FleetDM as your MDM solution, follow the steps to declare the FleetDM domain, create the Fleet application with necessary permissions, and set FleetDM as the default MDM for new devices in the Azure portal.

Find here all information related to Windows Autopilot and Zero-Touch Deployment on Windows with Factorial IT.

 

If you are currently using Intune as your MDM solution to manage your IT infrastructure and plan to switch to FleetDM (Factorial IT's MDM), you will need to perform a series of operations in the Microsoft Azure console with administrative rights to:

  • Declare the domain used by FleetDM as legitimate with Azure (e.g. {company}.mdm.getprimo.com)
  • Create the Fleet application and grant it the necessary permissions to act as an MDM
  • Configure Azure to manage new devices through FleetDM instead of Intune

 

Declaring the FleetDM Domain

  1. Sign in with an administrator account at: https://portal.azure.com/
  2. Search for and click on Domain names
  3. Click on + Add custom domain
  4. In the field, enter {company}.mdm.getprimo.com (i.e. acme.mdm.getprimo.com, contact support (factorial-factorial-support@getprimo.com) if you don't know this domain name)
  5. Share with us the value of the Destination or routing address field (in the format MS=ms12345678)
  6. Wait for our response (maximum 2 business days) before continuing with the procedure
  7. You can then click on Verify

 

Creating the FleetDM Application

  1. Sign in with an administrator account at: https://portal.azure.com/
  2. Search for Mobility (MDM and MAM)
  3. Choose + Add application, then select + Create your own application
  4. Enter Fleet as the application name and click Create
  5. Fill in
  6. Click Save
  7. Return to Mobility (MDM and MAM)
  8. Click on the Fleet application then on Custom MDM application settings
  9. Click on the link below Application ID URI then click Edit
  10. Enter your Fleet instance address (https://{company}.mdm.getprimo.com) and click Save
  11. Choose API permissions then Add a permission
  12. Click on Microsoft Graph then on Delegated permissions, and select:
    • Group > Group.Read.All
    • Group > Group.ReadWrite.All
    • and click Add permissions
  13. Then return to API permissions and Add a permission, and choose Microsoft Graph again
  14. This time, click on Application permissions, and add the following permissions:
    • Device > Device.Read.All
    • Device > Device.ReadWrite.All
    • Directory > Directory.Read.All
    • Group > Group.Read.All
    • User > User.Read.All
    • and click Add permissions
  15. Once back on the API permissions screen, click on Grant admin consent for ACME

The Fleet application is now registered as a legitimate MDM with the Azure portal.


 

Setting FleetDM as the Default MDM for New Devices

  1. Sign in with an administrator account at: https://portal.azure.com/
  2. Go to Mobility (MDM and MAM)
  3. Click on Microsoft Intune
  4. In MDM user scope, select None
  5. In MAM user scope, select None
  6. Click Save
  7. Go to Mobility (MDM and MAM)
  8. Click on Fleet
  9. In MDM user scope, select All
  10. In MAM user scope, select All
  11. Click Save

The Fleet application is now set as the MDM that will handle new devices in the Azure portal.

Note: If you started enrolling devices in Factorial IT/FleetDM before performing these steps, please let us know so we can force the MDM change from Intune to FleetDM by running a script (otherwise the machine will be in an inconsistent state that may affect the Factorial IT experience).

 

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice