Skip to main content
Cimento deploys the agent to your Windows fleet over Microsoft Graph. A Microsoft Entra Global Administrator grants access once, you choose a group, and Cimento uploads the package to Intune and assigns it. Nothing is downloaded or distributed by hand.
This flow covers Windows PCs. Macs enrolled in Intune are not covered; deploy those through a macOS MDM.

Prerequisites

  • A Microsoft Entra Global Administrator for the one-time consent. Cimento never receives or stores Microsoft credentials.
  • A security-enabled Entra group containing the pilot PCs. Intune scopes app assignments to security-enabled groups; distribution groups and default Microsoft 365 groups cannot be used.

Steps

1

Grant consent

Under Admin → Integrations → AI agents → Microsoft Intune, click Grant consent and sign in as a Global Administrator. Tick Consent on behalf of your organization. Without it the permissions apply only to your own account and the deployment fails.
2

Verify

Cimento makes read-only Graph calls to confirm the consent took effect and to list the security-enabled groups you can deploy to.
3

Deploy

Search for and choose a group. The search matches from the start of the group name, as in the Entra portal. Cimento uploads the Windows package to Intune as a Win32 app named Cimento Telemetry, assigns it to the group as a required install, and installs it in System context. Nothing is installed until you click Deploy. The page then tracks install and check-in status per device.

Permissions granted and why

All three are Microsoft Graph application permissions, granted tenant-wide by the consent step. Cimento does not request DeviceManagementConfiguration.Read.All or any permission on mail, files or users.

What lands on each PC

  • Signed binaries under C:\ProgramData\Cimento\bin and a per-user scheduled task that runs the drain every five minutes and at logon.
  • Hook configuration for Claude Code and Codex written machine-wide as SYSTEM; the Cursor hook written in the signed-in user’s profile.
  • The user’s email resolved from the signed-in user’s UPN, so one assignment serves every user without per-user configuration or extra Graph permissions.
  • The Intune detection rule is the registry string HKLM\SOFTWARE\Cimento\Telemetry\Version. Installer diagnostics are written to C:\ProgramData\Cimento\logs\install.log.
Installation needs an interactive user session. If Intune attempts it at the login screen the installer exits nonzero and Intune retries later. See How it works for signing details and the EKU to pin in WDAC policies.

Disconnecting

Disconnect in Cimento uninstalls the agent from the targeted PCs and removes the Win32 app and assignment Cimento created before deleting the stored consent.