Getting Started
Mobile Device Management (MDM)
Overview
Feha GRC supports integration with two Mobile Device Management (MDM) options:
- Feha MDM – Feha's own MDM solution, designed to provide more detailed and near real-time device information.
- Microsoft Intune – Microsoft's built-in MDM solution, which can be integrated with Feha GRC if the organization already uses Microsoft Intune.
Both options allow Feha GRC to collect device security information and use it for monitoring, compliance, and risk management. However, each option has different capabilities and requirements.
Comparison
| Capability | Feha MDM | Microsoft Intune |
|---|---|---|
| Device information | ✅ Available | ✅ Available |
| Real-time information | ✅ Yes | ❌ No |
| Antivirus status monitoring | ✅ Real-time | ⚠️ Based on Intune synchronization |
| Installed applications | ✅ Available | ❌ Not available |
| Web browser version | ✅ Available | ❌ Latest version not available |
| Screen lock information | ⚠️ Not available yet | ✅ Available |
| Requires additional MDM software/package | ✅ Yes, through FleetDM | ❌ No, if Intune is already implemented |
| Existing Intune devices can be synchronized | N/A | ✅ Yes |
| Synchronization interval | Real-time | Approximately every 8 hours |
Important Note
The choice between Feha MDM and Microsoft Intune does not mean that one solution is universally better than the other. The appropriate option depends on the organization's existing MDM infrastructure and the level of device information required.
Feha MDM provides more detailed and real-time device monitoring capabilities, including installed applications and web browser versions. However, it currently requires the deployment of the Feha MDM package through FleetDM and does not yet support screen lock information.
Microsoft Intune provides a simpler integration for organizations that already use Intune and supports screen lock information. However, some device information is not available through the integration, and device data is synchronized according to Intune's synchronization schedule rather than in real time.
As Feha MDM continues to be developed, additional device information, including screen lock status, may become available in future releases.
Integration
Feha GRC can integrate with Microsoft Intune to synchronize device management information from the organization's Microsoft Intune environment.
This integration allows Feha GRC to retrieve relevant device information and use it for device monitoring, security assessment, compliance monitoring, and compliance reporting.
Onboarding
The initial onboarding process is performed when a company account is used for the first time. The following activities are required to complete the setup:

- Log in using the company account for the first time.
- Complete the required fields in the Welcome & Overview section, then click Next to proceed to the Company Details section.
- Complete all required company information, including the Legal URLs & Contact section.
- In the Configuration section, synchronize and configure the values required by the company for Mobile Device Management (MDM) settings.
- Retrieve and synchronize user data based on the company's employee list through User Management.
- Click Complete Setup to finalize the onboarding process.
- After the setup is completed, the user is redirected to the Dashboard. From the Dashboard, the user can access Device Monitoring to view device configuration and management data for company employees' computers.
Settings
The Microsoft Intune integration can be configured through the company settings by a company administrator.

- Log in as a Company Admin.
- Open the Profile menu.
- Select Settings.
- Navigate to the Company Settings tab.
- Select Microsoft Intune in the MDM Provider field.
- Click Sync Now to initiate the synchronization process.
- Wait until the synchronization process is completed.
- Verify the synchronized Microsoft Intune data in the Device Monitoring page.
Vendor Management
Microsoft Intune can be configured as a vendor and integrated with FehaGRC to enable device data synchronization, scanning, and compliance reporting.

- Navigate to Vendor Management and open the Vendor Template submenu.
- Search for Microsoft Intune in the vendor template list.
- Complete the required Microsoft Intune information in the Add Vendor Template form.
- Open the Microsoft Intune Vendor Detail page.
- Navigate to the Integration tab.
- Configure the integration by completing the required fields using the corresponding values and credentials from the company's Microsoft Intune account.
- Initiate data synchronization between Microsoft Intune and FehaGRC.
- After synchronization is completed, FehaGRC can retrieve and scan Microsoft Intune device data and configuration information.
- The synchronized data can then be used by FehaGRC to perform compliance assessments and generate compliance reports related to employee devices and their security configurations.
Security and permissions
Security is one of the key considerations in our Intune integration. FEHA follows a least-privilege approach, so the integration only requests the permissions required to read the device and compliance information needed by the GRC platform.
The Intune integration uses read-only access. FEHA does not require high-level administrative access to your Intune environment and does not modify devices, policies, or other Intune configurations.
This approach minimizes the potential impact of the integration and provides an additional layer of security for your environment.
Synchronization Information in Intune
In Intune Device information is synchronized approximately every 8 hours. This is not real-time synchronization because the integration does not request the permissions required to actively manage or trigger updates on devices.