> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Agent Hub with Microsoft Intune

> Grant Cimento tenant-wide consent to three Microsoft Graph permissions so it can deploy the endpoint agent to Windows PCs in an Entra security group.

Cimento deploys the agent to your Windows fleet over Microsoft Graph. A Microsoft Entra Global Administrator grants access once, you choose a group, and Cimento uploads the package to Intune and assigns it. Nothing is downloaded or distributed by hand.

<Note>
  This flow covers Windows PCs. Macs enrolled in Intune are not covered; deploy those through a macOS MDM.
</Note>

## Prerequisites

* A **Microsoft Entra Global Administrator** for the one-time consent. Cimento never receives or stores Microsoft credentials.
* A **security-enabled Entra group** containing the pilot PCs. Intune scopes app assignments to security-enabled groups; distribution groups and default Microsoft 365 groups cannot be used.

## Steps

<Steps>
  <Step title="Grant consent">
    Under **Admin → Integrations → AI agents → Microsoft Intune**, click **Grant consent** and sign in as a Global Administrator. Tick **Consent on behalf of your organization**. Without it the permissions apply only to your own account and the deployment fails.
  </Step>

  <Step title="Verify">
    Cimento makes read-only Graph calls to confirm the consent took effect and to list the security-enabled groups you can deploy to.
  </Step>

  <Step title="Deploy">
    Search for and choose a group. The search matches from the start of the group name, as in the Entra portal. Cimento uploads the Windows package to Intune as a Win32 app named **Cimento Telemetry**, assigns it to the group as a required install, and installs it in System context. Nothing is installed until you click **Deploy**. The page then tracks install and check-in status per device.
  </Step>
</Steps>

## Permissions granted and why

All three are Microsoft Graph application permissions, granted tenant-wide by the consent step.

| Permission | Purpose |
| - | - |
| `DeviceManagementApps.ReadWrite.All` | Uploads the agent as a Win32 app, assigns it to the group, and updates it in place on each release. |
| `DeviceManagementManagedDevices.Read.All` | Reads per-device install status so the rollout can be reported. |
| `Group.Read.All` | Lists security-enabled groups so you can choose a deployment target, and reads their membership for per-device progress. |

Cimento does not request `DeviceManagementConfiguration.Read.All` or any permission on mail, files or users.

## What lands on each PC

* Signed binaries under `C:\ProgramData\Cimento\bin` and a per-user scheduled task that runs the drain every five minutes and at logon.
* Hook configuration for Claude Code and Codex written machine-wide as SYSTEM; the Cursor hook written in the signed-in user's profile.
* The user's email resolved from the signed-in user's UPN, so one assignment serves every user without per-user configuration or extra Graph permissions.
* The Intune detection rule is the registry string `HKLM\SOFTWARE\Cimento\Telemetry\Version`. Installer diagnostics are written to `C:\ProgramData\Cimento\logs\install.log`.

Installation needs an interactive user session. If Intune attempts it at the login screen the installer exits nonzero and Intune retries later. See [How it works](/agent-hub/how-it-works#code-signing) for signing details and the EKU to pin in WDAC policies.

## Disconnecting

**Disconnect** in Cimento uninstalls the agent from the targeted PCs and removes the Win32 app and assignment Cimento created before deleting the stored consent.
