1
Connect
Sign in with Microsoft. We use delegated, read-only Graph permissions and never persist tenant configuration data.
Export policies, settings, and assignments as audit-ready PDFs or Word documents, with broad coverage and clear collection status.
Read-only access. Tenant data is processed transiently and never persisted. /
Replace screenshots, copy-pasting, and manual formatting with a finished report in minutes.
Policies, apps, updates, enrollment, RBAC, tenant settings, connectors, and specialist resources.
Delegated OAuth, sensitive-value redaction, in-browser document generation, and no persistent tenant data storage.
How it works
1
Sign in with Microsoft. We use delegated, read-only Graph permissions and never persist tenant configuration data.
2
Pick configurations by type, search, or select all. Assignments and filters included.
3
Download a professional PDF or Word document with settings, ADMX values, script metadata, and group targeting. Sensitive values stay redacted.
Security
Our application server transiently collects, normalizes, and redacts Microsoft Graph responses. It does not persist your tenant configuration, access token, or generated documents.
Delegated, read-only permissions
Microsoft Graph scopes that can read your Intune configuration, never change it.
Sensitive values redacted
Script bodies, passwords, tokens, payloads, QR codes, and configuration-file contents are removed before dashboard display or export.
Reports generated in your browser
PDF and Word documents are built locally on your device, not on a server.
Nothing uploaded, nothing stored
Configuration data is fetched during your session and discarded when you leave.
Revoke access anytime
Remove the app from Entra ID enterprise applications, or simply sign out.
How your data flows
Microsoft Graph API
Your Intune tenant, delegated read-only access
Transient application processing
Collects, normalizes, and redacts responses without persistent tenant storage
Your browser
Shows collected sections and builds the report locally
Your PDF or Word file
Saved directly to your device
Complete coverage
Complete tenant detail, professional exports, and a security model designed for IT teams.
Core policies plus 36 additional Graph resource collections spanning apps, updates, enrollment, RBAC, tenant settings, connectors, and more.
Add your company logo, colors, headers, footers, and confidentiality notices to every report.
Group targets and filters resolved for clarity, with optional counts by platform.
Download polished PDF or DOCX documents, ready for audits, handovers, and archives.
Partial and failed Graph collections stay visible with their endpoint, status, and permission hint instead of looking empty.
Questions, answered
The Intune Documentation Generator is a free, read-only tool that collects your Microsoft Intune configuration through Microsoft Graph and turns it into a PDF or Word report. It covers the original policy areas plus 36 additional resource collections across updates, scripts and remediations, enrollment and provisioning, apps, assignments and RBAC, tenant settings, connectors, and specialist policies. The exact resources returned depend on your tenant, licensing, and permissions.
Simply sign in with your Microsoft account, select the Intune configurations you want to document, and click Export. The tool automatically generates a professional PDF report with all settings, assignments, and group configurations in minutes.
Yes, it's completely free. No hidden fees, no premium tiers, no credit card required. You can generate unlimited Intune documentation reports at no cost.
We use Microsoft OAuth 2.0 with delegated, read-only access. The application server processes Graph responses transiently to collect, normalize, and redact sensitive values, but it does not persist your tenant configuration or access token. PDF and DOCX generation happens in your browser, and generated documents are not uploaded or stored by us.
Coverage includes device configurations, Settings Catalog, compliance, security baselines, administrative templates, scripts and remediations, app protection and configuration, managed apps, Windows updates, enrollment and Autopilot, assignment filters, RBAC, tenant and service settings, connectors, and specialist policies. Conditional Access is optional and requested separately with Policy.Read.All.
The dashboard keeps any successfully collected sections and clearly marks partial or failed collections. Warnings include the affected section, endpoint, status code, and a permission hint when available, so a failed request is not presented as a confirmed empty result.
No. Sensitive values such as script bodies, passwords, tokens, pre-shared keys, QR-code payloads, encoded configuration files, and large app icons are replaced with [Redacted] before data reaches the dashboard or an export. The report retains useful metadata so reviewers can still identify the resource.
A number of Intune administration resources needed for complete documentation are currently exposed through Microsoft Graph beta. The tool uses those endpoints only for delegated, read-only collection and isolates failures by resource so one unavailable endpoint does not hide the rest of the report.
This is a common alert when an app requests the standard 'offline_access' permission from Microsoft identity (used to refresh tokens without repeatedly prompting you). It does NOT grant extra data access beyond your approved read-only scopes, and we use only delegated permissions (no application permissions). Tokens are kept in your browser session, and we do not store tenant data.
Collection time depends on tenant size, Graph throttling, and the resources available in your environment. The dashboard streams sections as they finish and shows live progress, then lets you export the successfully collected data even when another section reports a warning.
Yes, you can customize your documentation with branding options including company logo, custom colors, headers, footers, and confidentiality notices. You can also select specific configurations to include or exclude from the report.
Try it now
Sign in securely with Microsoft and export a professional report in minutes.