Microsoft Intune can enrol devices, configure them, apply policies and monitor them technically. It shows managed devices, operating-system and hardware information, compliance states and — depending on enrolment and platform — user relationships too. For many IT teams Intune is therefore the most important source for the current technical state of their Windows, macOS and mobile devices.

A complete IT asset management practice answers further questions, though. Who owns a device? What did it cost? What warranty still applies? Who physically took delivery of it? Where are the docking station, monitor and accessories? What has to come back when someone leaves? And how does the history stay traceable once a device has been removed from Intune?

The short answer is therefore: Intune does not replace an ITAM — and an ITAM does not replace Intune. The two systems have different jobs. Combined sensibly they deliver a fuller picture without IT having to maintain the same device data by hand in two places.

What Intune already covers well

Intune is a platform for unified endpoint management. Its focus is the ongoing operation of endpoints. Depending on device type, operating system and configuration that includes, among other things:

  • enrolling devices and taking them into management,
  • distributing configuration and security policies,
  • deploying or removing applications,
  • evaluating compliance and device states,
  • showing technical device attributes and last check-in times,
  • triggering actions such as lock, wipe or retire,
  • showing primary or registered user relationships where Intune holds them.

This information is operational: it helps judge whether an endpoint is managed, reachable and compliant. Intune should stay the leading source for exactly that. An ITAM should not try to reproduce the current compliance state by hand.

Which questions only become complete in IT asset management

An asset's lifecycle often begins before Intune enrolment and does not automatically end when it is removed from the MDM. IT needs further information in those phases.

Procurement and commercial data

Order reference, purchase date, price, supplier, cost centre and warranty are not part of an endpoint management system's core job. They still matter for replacement planning and budget conversations. In an ITAM that data can sit directly on the asset instead of being spread across an order, an invoice and several spreadsheets.

Physical handover and responsibility

A user relationship in Intune is valuable but not in every case the same thing as a documented handover. Shared devices, stock devices, spare devices or a laptop in transit can be technically enrolled without anyone currently being responsible for them. Conversely, monitors, headsets, keys or other unmanaged items may have been handed out together with a laptop.

An ITAM assignment therefore deliberately documents who received or returned which specific asset and when. Serial number, accessories and condition can be maintained separately from the technical user context.

History beyond MDM membership

After a replacement, a return or a disposal a device can disappear from Intune. Its story stays relevant for internal documentation all the same: earlier assignments, repairs, status changes, warranty and whereabouts. The ITAM preserves this organisational lifecycle even when the device is no longer actively managed.

Unmanaged assets and accessories

Not everything of value carries an MDM agent. Network hardware, monitors, peripherals, components, consumables and software licences also need structured record-keeping, depending on the company. An ITAM carries these inventory classes alongside the devices synchronised from Intune.

Onboarding and offboarding

When someone joins it is not only about device configuration. IT has to pick available hardware, assemble accessories, document handovers and, where required, obtain approvals. When someone leaves, every assigned item must be visible, returns tracked and licences released for the next use. Intune supplies technical actions; the ITAM coordinates the operational process around them.

Intune or ITAM: a practical division of labour

Question Leading system
Is the device enrolled and when did it last check in? Intune
Which configuration and compliance policies apply? Intune
Which technical device attributes does the endpoint report? Intune
Who took delivery of the physical device and when? ITAM
What was paid and when does the warranty end? ITAM
Which monitors, docks or other items belong to the handout? ITAM
Which stations did the asset pass through during its lifecycle? ITAM
What has to be returned at offboarding? ITAM, complemented by actions in Intune and identity systems

"Leading system" does not mean the information may only be visible in one place. It means: one source is responsible for updating it, the other takes the values it needs by synchronisation. That decision prevents contradictory corrections and unclear responsibilities.

How to build the connection without duplicate upkeep

1. Set the goal and the scope

Start with a concrete question rather than with every available field. A good first goal reads, for example: "Every actively managed laptop should appear in the inventory and be assignable to a responsible person." Decide which platforms, ownership types and device categories are to be included at first.

At the same time define what deliberately should not happen automatically. A user reported by Intune can be a technical relationship; whether that becomes a physical handover without review depends on your process.

2. Check your unique identifiers

Serial numbers are often suitable for recognition but are not complete or consistent in every data set. Before the first reconciliation check in particular:

  • missing or generic serial numbers,
  • devices enrolled more than once,
  • differing spellings of manufacturer and model,
  • test, virtual and personally owned devices,
  • devices already created manually in the ITAM.

A small test run makes it visible whether new records are created or existing devices are updated. Only once that logic is right should the whole estate be synchronised.

3. Separate technical and organisational fields

Let Intune update the technical attributes it actually observes. Purchase price, order number, warranty, storage location, internal status or documented handovers are maintained in the ITAM instead. That way a later sync does not overwrite lifecycle data added by hand.

A simple field list with the columns "source", "target", "update rule" and "owner" is enough for this decision. It is useful later when something goes wrong, too: the team knows immediately where a wrong value has to be corrected.

4. Test people matching separately

Device and people data often come from different sources. Intune knows the technical user context; an HR or identity system knows joining date, leaving date, department and organisational responsibility. Check which stable attribute people are matched on — usually a unique business email address or another internally defined identifier.

Test the typical edge cases: name changes, external people, shared devices, accounts without a mailbox and already deactivated users. Automatic matching only helps when its exceptions stay visible.

5. Define operation and error handling

An integration needs an owner. Decide who checks failed synchronisations, how often they should run and which change requires a manual review. If the MDM goes down, the last known inventory view must not silently count as current.

After going live, check samples regularly: the number and kind of newly created devices, records without a serial number, devices without an organisational assignment and unexpected status changes. Those checks usually say more than a single big "clean-up" before launch.

Common mistakes when combining the two

Taking everything from Intune as an asset without review. Virtual, private, duplicated or briefly enrolled devices can inflate the inventory needlessly. Filters and a test run belong before the full synchronisation.

Equating the Intune user with a confirmed handout. The technical user relationship is a strong signal but not a universal delivery receipt. Shared devices and device swaps need a clear process.

Rebuilding purchase and warranty data in the MDM. Such fields are often maintained irregularly there. Keep organisational and commercial data in the system responsible for the lifecycle.

Removing deleted MDM devices from the history. "No longer managed" and "may disappear from the inventory record" are two different decisions.

Automating without accountability. Even a technically stable sync produces exceptions. Without a responsible person they pile up and gradually erode the quality of the inventory.

Connecting Intune with AssetNode

AssetNode can synchronise devices from Microsoft Intune into the central inventory. There you complement the technical data with categories, commercial information, status, assignments and further lifecycle data. Employees, accessories, licences and assets not managed by MDM stay visible in the same workspace.

The sensible way in is small: first create or import the people you need, then connect Intune and check a manageable group of synchronised devices. After that you can add rules for assignments, notifications or follow-up tasks step by step.

Start with AssetNode for free — the managed cloud is free for up to 100 assets. For internal use you can also self-host the fair-code, source-available version, with no limit on the number of assets.