You can connect your organization's mobile device management (MDM) provider to Firstbase to bring device data into your inventory without manual reconciliation. Firstbase supports Jamf, Microsoft Intune, Iru, and JumpCloud. After you connect a provider and complete the initial device import, Firstbase syncs MDM data into inventory on a regular schedule so you can view enrollment status, compliance, and security details alongside your existing asset information.
This guide walks you through connecting an MDM provider, choosing which devices to import, and where to find synced MDM data in Firstbase.
Connect your MDM provider
- In the Firstbase app, go to API & Integrations → Integrations and open the Available tab.
- Under Device Management, select your provider: Jamf, Microsoft Intune, Iru, or JumpCloud.
- Enter your provider credentials:
- Jamf: Subdomain, Client ID, Client Secret
- Intune: Tenant ID, Client ID, Client Secret
- Iru: Domain and API Token
- JumpCloud: API Key
- Click Continue to validate your credentials and move to data preferences.
- On the Data preferences step, choose whether to sync Installed applications. Device security data (enrollment, compliance, disk encryption, and related fields) is always synced and cannot be turned off.
- On the Review devices step, review devices discovered in your MDM. Select which devices to import and resolve any assignment or brand mismatches.
- Click Submit import to complete the initial import.
After the import finishes, your provider appears on the Active tab and ongoing sync begins.
Note: You can connect one instance per provider type (for example, Jamf and Intune together, but not two Jamf instances). If you close the wizard before submitting the import, return to the Active tab and use Select devices on the integration card to resume where you left off.
Review and import devices
On the Review devices step, Firstbase shows devices discovered in your MDM. Each device is grouped so you know what needs attention before import.
Review groups
| Group | What it means | What to do |
|---|---|---|
| Need attention | Assignment mismatch or new device not yet in Firstbase | Resolve assignee or brand before importing |
| Ready to link | Device exists in both systems with matching assignments | Select devices to include |
| Unassigned in MDM | No assignee in your MDM | Cannot be imported |
| Missing serial | No usable serial number in MDM | Cannot be imported |
Before you submit
- Use the checkboxes to select which devices to import.
- For assignment mismatches, choose whether to keep the Firstbase assignee or apply the MDM assignee.
- For new devices, assign a person or office. You can create a new person if the MDM user is not yet in Firstbase.
- If the MDM manufacturer does not map cleanly to a Firstbase brand, use the brand picker to override it.
What happens when you import
- New devices (in MDM only) are added to Firstbase as customer-supplied inventory with MDM metadata.
- Existing devices (matching serial number) are linked and their MDM data is updated.
- Assignees are set during import only. Ongoing sync does not change person or office assignment in Firstbase, even if MDM assignment data changes later.
Device types
Firstbase imports devices into the correct inventory category (Computer, Tablet, Mobile Phone, or Drawing Tablet) based on what your MDM reports. Unsupported device types are skipped.
- Jamf and JumpCloud sync computers only.
- Intune and Iru can include computers, tablets, and mobile phones.
You must complete the initial import before scheduled sync begins. If you leave the wizard early, go to the Active tab and click Select devices on the integration card to finish.
View MDM data in Firstbase
After devices are imported, MDM data appears in two places: the Asset Management list and the Asset Details modal.
Asset Management list
MDM columns are hidden by default. Open the column picker to add any of these:
| Column | Description |
|---|---|
| MDM Provider | Connected provider (Jamf, Intune, Iru, or JumpCloud) |
| Enrollment Status | Whether the device is actively managed |
| Compliance Status | Pass or fail as reported by your MDM |
| Last MDM Check-In | When the device last checked in with your MDM |
| OS Version | Current OS version from your MDM |
| Disk Encryption | Whether disk encryption is enabled |
| Battery Health | Battery capacity percentage (where available) |
You can also filter by MDM provider, enrollment status, compliance, check-in date, and whether a device is connected to MDM.
Asset Details (MDM tab)
- Go to Asset Management.
- Find the device (search by serial number, assignee, or use MDM filters).
- Click the asset to open Asset Details.
- Select the MDM tab.
The MDM tab shows synced data such as hostname, OS version, last check-in, enrollment status, compliance, disk encryption, firewall status (where available), security score, and installed applications (when installed-applications sync is enabled).
The MDM tab is available for Computer, Tablet, Mobile Phone, and Drawing Tablet assets linked to an MDM provider. It does not appear for other categories (for example monitors) or when the device is not connected to MDM.
Note: Available fields depend on your MDM provider. If your MDM does not report a field, it is omitted from Firstbase rather than shown as empty.
Manage ongoing sync
After the initial import is complete, Firstbase keeps your inventory in sync with your MDM automatically.
Sync frequency
| Method | Providers | Details |
|---|---|---|
| Scheduled | All providers | Runs hourly |
| Real-time | Jamf only | Updates via webhooks when webhook registration succeeds |
| Manual | All providers | Use Sync now on the Active integration card |
Intune, Iru, and JumpCloud rely on the hourly schedule and Sync now for immediate updates.
What gets synced
- Device metadata (hostname, OS version, enrollment status, compliance, security data)
- New MDM enrollments, if auto-create is enabled in integration settings
- Installed applications, if you enabled that preference during setup
What does not get synced
- Device assignees. Person or office assignment is set during the initial import only. Ongoing sync does not update assignees in Firstbase, even if MDM assignment data changes.
Devices are matched by serial number. If a device exists in both systems, Firstbase updates MDM metadata only. Devices in Firstbase but not in your MDM are left unchanged.
Firstbase does not write data back to your MDM. The integration is read-only.
Manage your integration
On the Active tab under API & Integrations → Integrations, each connected MDM provider shows:
- Connection status and last sync time
- Number of devices synced
- Sync now for an immediate refresh
- Integration settings, including auto-create for new MDM enrollments
If credentials expire, use Re-authenticate on the integration card to enter updated credentials. The Activity tab shows sync job history.
Frequently asked questions
Which MDM providers does Firstbase support?
Firstbase supports Jamf, Microsoft Intune, Iru (previously known as Kandji), and JumpCloud. Additional MDM providers are not supported at this time.
Can I connect more than one MDM provider at the same time?
Yes. You can connect one instance per provider type. For example, you can connect Jamf and Intune together, but not two separate Jamf instances.
Why can't I import some devices from my MDM?
Some devices cannot be imported:
- Unassigned in MDM: The device has no assignee in your MDM. Assign a user in your MDM before importing.
- Missing serial: The MDM record has no usable serial number. Firstbase matches devices by serial number, so these cannot be imported.
- Unsupported device type: Firstbase only imports devices that map to Computer, Tablet, Mobile Phone, or Drawing Tablet categories.
Jamf and JumpCloud sync computers only. Intune and Iru can include computers, tablets, and mobile phones.
Can Firstbase write data back to my MDM?
Not yet. The MDM integration is read-only today. Firstbase pulls data from your MDM but does not push changes back.
That means Firstbase cannot currently update MDM assignments, remove devices from MDM, deprovision licenses, or trigger remote lock, wipe, or unlock commands through this integration.
Two-way sync is planned for future updates, including writing data back to your MDM and supporting offboarding and remote actions. We will update this article as those capabilities become available.
What happens if a device is in Firstbase but not in my MDM?
The Firstbase inventory item is left unchanged. MDM sync only updates devices that exist in your connected MDM. Use the MDM Connected filter in Asset Management to find devices without an active MDM connection.
What happens if MDM and Firstbase show different assignees?
During initial import: Devices with mismatched assignees appear under Need attention in the import preview. You must choose the correct assignee before importing.
After import: Firstbase does not update assignees from ongoing sync. Scheduled sync, Jamf webhooks, and Sync now refresh MDM metadata (hostname, OS, compliance, security fields, etc.) but leave the current Firstbase assignee unchanged.
If your MDM later shows no assignee, the Firstbase assignee is not cleared.
How do I troubleshoot sync errors?
- Go to API & Integrations → Integrations and open the Active tab.
- Find your MDM provider card and check the connection status, last sync time, and any error message.
- Click Sync now to retry, or check the Activity tab for sync job history.
| Error | Likely cause | What to do |
|---|---|---|
| Authentication expired | API credentials revoked or expired | Use Re-authenticate and enter updated credentials |
| API rate limits | Too many requests to the MDM API | Wait and use Sync now to retry |
| Device match failures | Serial number mismatch or missing serial | Verify serial numbers in both systems |
| Import not completed | Initial import was not submitted | Return to the integration card and click Select devices to finish |
If issues persist, confirm your credentials are valid in your MDM admin console and that the device is enrolled with a valid serial number.
Comments
0 comments
Please sign in to leave a comment.