Getting Started

Mobile Device Management (MDM)

Overview

Feha GRC supports integration with two Mobile Device Management (MDM) options:

  1. Feha MDM – Feha's own MDM solution, designed to provide more detailed and near real-time device information.
  2. Microsoft Intune – Microsoft's built-in MDM solution, which can be integrated with Feha GRC if the organization already uses Microsoft Intune.

Both options allow Feha GRC to collect device security information and use it for monitoring, compliance, and risk management. However, each option has different capabilities and requirements.

Comparison

CapabilityFeha MDMMicrosoft Intune
Device information✅ Available✅ Available
Real-time information✅ Yes❌ No
Antivirus status monitoring✅ Real-time⚠️ Based on Intune synchronization
Installed applications✅ Available❌ Not available
Web browser version✅ Available❌ Latest version not available
Screen lock information⚠️ Not available yet✅ Available
Requires additional MDM software/package✅ Yes, through FleetDM❌ No, if Intune is already implemented
Existing Intune devices can be synchronizedN/A✅ Yes
Synchronization intervalReal-timeApproximately every 8 hours

Important Note

The choice between Feha MDM and Microsoft Intune does not mean that one solution is universally better than the other. The appropriate option depends on the organization's existing MDM infrastructure and the level of device information required.

Feha MDM provides more detailed and real-time device monitoring capabilities, including installed applications and web browser versions. However, it currently requires the deployment of the Feha MDM package through FleetDM and does not yet support screen lock information.

Microsoft Intune provides a simpler integration for organizations that already use Intune and supports screen lock information. However, some device information is not available through the integration, and device data is synchronized according to Intune's synchronization schedule rather than in real time.

As Feha MDM continues to be developed, additional device information, including screen lock status, may become available in future releases.

Integration

Feha GRC can integrate with Microsoft Intune to synchronize device management information from the organization's Microsoft Intune environment.

This integration allows Feha GRC to retrieve relevant device information and use it for device monitoring, security assessment, compliance monitoring, and compliance reporting.

Onboarding

The initial onboarding process is performed when a company account is used for the first time. The following activities are required to complete the setup:

  1. Log in using the company account for the first time.
  2. Complete the required fields in the Welcome & Overview section, then click Next to proceed to the Company Details section.
  3. Complete all required company information, including the Legal URLs & Contact section.
  4. In the Configuration section, synchronize and configure the values required by the company for Mobile Device Management (MDM) settings.
  5. Retrieve and synchronize user data based on the company's employee list through User Management.
  6. Click Complete Setup to finalize the onboarding process.
  7. After the setup is completed, the user is redirected to the Dashboard. From the Dashboard, the user can access Device Monitoring to view device configuration and management data for company employees' computers.

Settings

The Microsoft Intune integration can be configured through the company settings by a company administrator.

  1. Log in as a Company Admin.
  2. Open the Profile menu.
  3. Select Settings.
  4. Navigate to the Company Settings tab.
  5. Select Microsoft Intune in the MDM Provider field.
  6. Click Sync Now to initiate the synchronization process.
  7. Wait until the synchronization process is completed.
  8. Verify the synchronized Microsoft Intune data in the Device Monitoring page.

Vendor Management

Microsoft Intune can be configured as a vendor and integrated with FehaGRC to enable device data synchronization, scanning, and compliance reporting.

  1. Navigate to Vendor Management and open the Vendor Template submenu.
  2. Search for Microsoft Intune in the vendor template list.
  3. Complete the required Microsoft Intune information in the Add Vendor Template form.
  4. Open the Microsoft Intune Vendor Detail page.
  5. Navigate to the Integration tab.
  6. Configure the integration by completing the required fields using the corresponding values and credentials from the company's Microsoft Intune account.
  7. Initiate data synchronization between Microsoft Intune and FehaGRC.
  8. After synchronization is completed, FehaGRC can retrieve and scan Microsoft Intune device data and configuration information.
  9. The synchronized data can then be used by FehaGRC to perform compliance assessments and generate compliance reports related to employee devices and their security configurations.

Security and permissions

Security is one of the key considerations in our Intune integration. FEHA follows a least-privilege approach, so the integration only requests the permissions required to read the device and compliance information needed by the GRC platform.

The Intune integration uses read-only access. FEHA does not require high-level administrative access to your Intune environment and does not modify devices, policies, or other Intune configurations.

This approach minimizes the potential impact of the integration and provides an additional layer of security for your environment.

Synchronization Information in Intune

In Intune Device information is synchronized approximately every 8 hours. This is not real-time synchronization because the integration does not request the permissions required to actively manage or trigger updates on devices.