Webinar: Managing Macs with Intune: security, scale, & the modern enterprise fleet
Register to attend
Reference

MDM integration

Petros Amoiridis

FreeProEnterprise

Connecting an MDM provider to your Workspace lets Workbrew enrich Device records with metadata from your MDM. On Pro and Enterprise plans, it also enables automatic Device Group sync.

Supported providers

ProviderDisplay nameRequired credentials
JamfJamfHost, API Client ID, API Client Secret
Iru (formerly Kandji)Iru (formerly Kandji)Host, API Token
SimpleMDMSimpleMDMAPI Secret Access Key
FleetFleetHost, API Token
JumpCloudJumpCloudAPI Token
Microsoft IntuneMicrosoft IntuneTenant ID, Client ID, Client Secret

All credentials are encrypted at rest. Providers that do not require a host use a fixed endpoint.

What connecting an MDM provides

Device metadata

Workbrew queries the MDM for each Device and stores the following fields:

FieldDescription
MDM device IDThe Device's unique identifier in the MDM
MDM user IDThe user assigned to the Device in the MDM, if any
MDM display nameThe assigned user's name or the Device name

This metadata is refreshed at most once per day per Device. When present, the MDM display name appears alongside the Device's serial number throughout the Workbrew Console and is included in Device search.

When a Device has an MDM device ID, the Workbrew Console shows a View on [provider] link that opens the Device's record in your MDM dashboard.

Device Group sync (Pro and Enterprise)

On paid plans, Workbrew automatically syncs Device Groups from your MDM every 6 hours. See MDM Device Group sync for the full sync schedule and behavior.

Connection validation

When you save MDM credentials, Workbrew performs a test API call against your MDM to verify connectivity. If the test fails, the credentials are not saved and an error is displayed:

ErrorMeaning
UnauthorizedThe API token or credentials are invalid or expired
ForbiddenThe credentials lack the required permissions
Not foundThe MDM host or API endpoint could not be reached
Connection failedA network or DNS error prevented the connection
SSL errorTLS certificate validation failed
Server errorThe MDM provider returned a server-side error

When credentials are changed, existing MDM metadata on all Devices is cleared and re-fetched from the new provider.