A Microsoft service principal, application ID f1346770-5b25-470b-88bd-d5744ab7952c and at times shown as Intune Autopilot ConfidentialClient, that has to be an owner of the device group used by Autopilot device preparation and enrolment time grouping.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Intune Provisioning Client in context, with comparison tables and the common traps.
Terms in this definition
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- Windows Autopilot device preparation
With this newer Autopilot approach, selected apps and scripts install during OOBE. It is targeted at user groups, and enrollment time grouping places each PC in a static group that the Intune Provisioning Client owns.
- Enrollment time grouping
An enrolment policy setting that puts devices into a static Microsoft Entra security group as they enrol, not later on, so their apps and policies are there at first check-in. The Intune Provisioning Client service principal owns the group.