Skip to content
All guidesCybermatic Endpoint Protection

Connect Microsoft Intune (optional) for full factory erase

One admin-consent click links your Intune tenant; remote wipes then also factory-erase enrolled Macs and Windows PCs.

  1. 1Who this is for: organizations already managing devices with Microsoft Intune (included in Microsoft 365 Business Premium, E3/E5, or Intune Plan 1). If you don't use Intune, skip this — Cybermatic's cryptographic wipe works without it.
  2. 2Prerequisites in your tenant: Intune licensed; for Macs, an Apple MDM push certificate configured in the Intune admin center (Devices → macOS → Enrollment → Apple MDM Push certificate — a ten-minute, any-Apple-ID step); the devices enrolled in Intune (Company Portal, or Apple Business Manager for supervised Macs). A device that isn't enrolled can't be erased by Intune.
  3. 3Connect: open Endpoint Protection → Settings → the 'Microsoft Intune (optional)' card → Connect Intune. You're taken to Microsoft's admin-consent page.
  4. 4Sign in as a Global Administrator of your Microsoft 365 / Entra tenant. Review the two permissions — 'Read Microsoft Intune devices' and 'Perform user-impacting remote actions on Microsoft Intune devices' — tick 'Consent on behalf of your organization', then Accept.
  5. 5Microsoft returns you to Cybermatic, which verifies it can reach your Intune and records the tenant. The card now reads Connected and shows how many managed devices Intune reports; devices are matched to Cybermatic by serial number, so no manual mapping.
  6. 6From then on, a remote wipe on an Intune-enrolled Mac or Windows PC does both: Cybermatic's own isolate-and-cryptographic-wipe within a minute, and Intune's EraseDevice for the full factory reset. The Response entry records whether Intune accepted the command.
  7. 7Disconnect any time from the same card. To remove Cybermatic's access entirely, delete the 'Cybermatic Endpoint Response' enterprise application in Microsoft Entra admin center → Enterprise applications.

Tip: No passwords are shared: consent grants Cybermatic's application identity two scoped permissions in your tenant, visible and revocable under Enterprise applications at any time.

More in Cybermatic Endpoint Protection