Renew secret key values for SCCM-Intune comanagement applications

  • Using Cloud Attach to setup co-management of between SCCM and Intune creates two main Applications in Application Registry/Enterprise Applications; ConfigMgrSvc_XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX and Cloud Management.
  • By default the Secret Key duration is set to one year and so you need to set a calendar reminder to create a new secret key even though you will receive a reminder about 15days to the expiration date.
  • To renew the secret keys, in SCCM, navigate to Administration>>>Azure Directory Tenants. Click on the Tenant Name to display the corresponding Applications at the bottom of the page.
  • Right-click on each of the Enterprise Applications and click on Renew Secret Key.
  • When presented with the Office 365 log in screen, enter your Microsoft Entra ID/Office 365 account which has a Global Administrator or Cloud Application Administrator role associated with it and log in. Complete the associated MFA if it has been setup.
  • Once the process is successful, you will be presented with popup in SCCM indicating the renewal has been successful.
  • Log into the Application Registry in Azure and verify that the new secret keys have been created in the two applications.
  • Note: Do not renew the secret keys from Application Registry/Enterprise Applications in Azure because it may not be able to sync with SCCM. Correct process is to renew the secret keys from the SCCM side.