how to sync the servicenow cmdb with intune inventory
Syncs the ServiceNow CMDB with Intune inventory so asset records match reality: Graph API device export, a scheduled import, and reconciliation rules for duplicates and retired devices. Use when the CMDB is stale or audits flag asset mismatches. Not for real-time device tracking.
TL;DR
Register an app with device-read rights, pull managed devices from Microsoft Graph on a daily schedule, and import them into the CMDB with serial number as the match key. Let Intune win on hardware facts and the CMDB win on assignment and owner. Reconcile, do not just append, or you get duplicate CIs.
Steps
- In Entra ID, register an app with the DeviceManagementManagedDevices.Read.All permission and grant admin consent. Expected: consent shows as granted in the Entra app registration.
- Pull the device list from Microsoft Graph: GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices, following the paging links until done. Expected: JSON rows with serial number, device name, OS, and compliance state.
- Write the field mapping: serial number to the CMDB serial field, Intune device name to CI name, compliance state to asset state. Expected: a one-page mapping table the team can review.
- Build the ServiceNow import as a scheduled REST import or the Graph connector, running daily. Expected: the import set completes and logs its row counts.
- Set reconciliation rules: match on serial number; Intune wins for hardware facts, the CMDB wins for assignment and owner. Expected: duplicates merge into one CI, retired devices flip to retired instead of being deleted.
- Verify: compare device counts between Intune and the CMDB computer class. Expected: within 2 percent; investigate the gap before calling it done.
Use this when
- CMDB asset records do not match the devices actually deployed
- Auditors ask for a trustworthy device inventory
- Refresh-cycle planning needs real counts
Not for this skill when
- Real-time location tracking (a daily sync is not real time)
- Unmanaged or BYOD devices (they never appear in Intune inventory)
Compatibility
- Microsoft Intune plus Entra ID; Microsoft Graph v1.0
- ServiceNow CMDB with import sets or the Graph spoke
Variants
Also sync Macs from Jamf
Same pattern with the Jamf Pro API as the source. Keep one source of truth per device type.
Hybrid shops with SCCM plus Intune
Pick the winner per device type up front. Two sources writing the same CI class is how duplicates are born.
Why it happens
CMDBs decay because nothing writes back to them. Intune already knows the truth about every managed device, so the sync is a pipe, not a project.
Edge cases
- Devices enrolled twice after a reimage: dedupe on serial number.
- Personal devices in Intune: filter by managed ownership so BYOD does not pollute the CMDB.
- Expired Graph credentials: use a service principal and put its secret rotation on a calendar.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_IJDaLnq3opv-veoPzAEtng
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.