This flow covers Windows PCs. Macs enrolled in Intune are not covered; deploy those through a macOS MDM.
Prerequisites
- A Microsoft Entra Global Administrator for the one-time consent. Cimento never receives or stores Microsoft credentials.
- A security-enabled Entra group containing the pilot PCs. Intune scopes app assignments to security-enabled groups; distribution groups and default Microsoft 365 groups cannot be used.
Steps
1
Grant consent
Under Admin → Integrations → AI agents → Microsoft Intune, click Grant consent and sign in as a Global Administrator. Tick Consent on behalf of your organization. Without it the permissions apply only to your own account and the deployment fails.
2
Verify
Cimento makes read-only Graph calls to confirm the consent took effect and to list the security-enabled groups you can deploy to.
3
Deploy
Search for and choose a group. The search matches from the start of the group name, as in the Entra portal. Cimento uploads the Windows package to Intune as a Win32 app named Cimento Telemetry, assigns it to the group as a required install, and installs it in System context. Nothing is installed until you click Deploy. The page then tracks install and check-in status per device.
Permissions granted and why
All three are Microsoft Graph application permissions, granted tenant-wide by the consent step.
Cimento does not request
DeviceManagementConfiguration.Read.All or any permission on mail, files or users.
What lands on each PC
- Signed binaries under
C:\ProgramData\Cimento\binand a per-user scheduled task that runs the drain every five minutes and at logon. - Hook configuration for Claude Code and Codex written machine-wide as SYSTEM; the Cursor hook written in the signed-in user’s profile.
- The user’s email resolved from the signed-in user’s UPN, so one assignment serves every user without per-user configuration or extra Graph permissions.
- The Intune detection rule is the registry string
HKLM\SOFTWARE\Cimento\Telemetry\Version. Installer diagnostics are written toC:\ProgramData\Cimento\logs\install.log.