Skip to content

PatchBee docs

Connecting an Intune tenant

PatchBee publishes into your Microsoft Intune tenant through a secure connection. You can connect more than one tenant and pick which to publish to each time.

Connect a tenant

  1. Go to Settings → Intune connections.
  2. Select Add connection.
  3. Choose how to authorise:
    • Admin consent (recommended): you are sent to Microsoft to approve the permissions PatchBee needs, then returned to the app.
    • Manual: enter an app registration's client ID and secret if your organisation prefers to create it yourself.
  4. Give the connection a friendly name and save.

Your stored credentials are encrypted and never shown again in full.

If consent fails

Just start again. Choosing Admin consent a second time picks up the attempt you already began instead of creating another connection, so an approval you abandoned, cancelled, or completed with the wrong account costs you nothing, and it never counts against the number of Intune tenants your plan includes. Only the newest approval link works, so if you left an earlier one open in another tab, close it and use the new one.

A connection that failed does not use up a slot either. If your first attempt left a failed connection in the list, you can still add your next one normally; the failed entry is only there for you to look at, and you can delete it whenever you like.

Example: an MSP connecting a second customer tenant

  1. Sign in with an account that has Intune admin rights in the customer tenant (or have their admin complete the consent step).
  2. Settings → Intune connections → Add connection → Admin consent, approve as the customer tenant admin, and name it after the customer, for example Contoso Ltd production.
  3. Every publish flow now offers both connections in its tenant step, and with MSP mode you can group connections under customers.

Next

With a tenant connected, you are ready to deploy: find an app in the catalog, then package and publish it.