The Microsoft Intune module addresses no addresses in your network but your
Microsoft tenant. Like Microsoft 365 it requires exactly one entry for that:
the Entra ID app registration through which access happens.
The wizard shows four steps for this module:
Basics › Entra ID App › Schedule › Summary
That is the same sequence of steps as with Microsoft 365, and it is the same
step: both modules choose their app from the same list.
The app registration
It is prepared under Scan › Credentials as an entry of the type
Entra ID App. How you create an entry, test access through Verify and renew
certificate and client secret is on
Microsoft 365 – the path
is the same for both modules.
In the Entra ID App step you choose the prepared entry in a searchable picker;
the second line per entry names the tenant. Without a selection the step stops.
A cloud scan runs over a gateway as well: the Basics step requires a gateway
and a job name for every module.
One job per module
Microsoft 365 and Microsoft Intune are two scan modules. The same entry can
supply both, but each module needs its own job – and therefore its own schedule.
If the client secret or the certificate expires, that affects both jobs at once,
because they hang on the same app. How you keep the date in view is on
Microsoft 365.
This module enters no targets – the scope follows from what the app is allowed to
see in the tenant. Which permissions are granted is shown by Verify in the
selection bar of the Credentials list: select the entry, then Verify.
Which types this scan produces is under
Cloud and Identity. After the first execution the
job detail shows under Last Scan Details what was captured – see
Managing Jobs.