Confidence-scored Primary User remediation for Intune

{{ headline }}

Affintra detects incorrect Intune Primary User assignments with a confidence-scoring model — Dominance, Margin, Consistency, Recency — and safely writes the fix back to Intune.

Book a demo See how it works ↓
✓ Read-only until you approve ✓ Live in 15 minutes ✓ Multi-tenant
Trusted by IT teams at
NORDVIKhelix.ioCanteraBLUEGRIDOstrafabvantor
The problem

Your Primary Users are lying to you

Whoever enrolled the device became its Primary User — the intern, the technician, the previous owner. Every downstream process trusts that field: self-service, licensing, compliance, security response. When it's wrong, everything built on it is wrong.

Before — what Intune thinks
LAPTOP-4471svc.deploy@corp.com
LAPTOP-2093j.mueller (left 2024)
DESKTOP-8812it.helpdesk@corp.com
After — who actually uses it
LAPTOP-4471a.krause · 97%
LAPTOP-2093t.osei · 94%
DESKTOP-8812m.lindqvist · 99%
0%
of Primary Users are wrong in a typical tenant
0
from consent to first full analysis
0
signals per verdict: Dominance, Margin, Consistency, Recency
0
writes without an audit trail. Ever.
How it works

From sign-in noise to a clean tenant

Four steps. No agents, no scripts, no CSV archaeology.

{{ s.num }}

{{ s.title }}

{{ s.body }}

Confidence scoring

A verdict you can defend, not a guess

Every device gets a confidence score built from four weighted signals over real sign-in behavior. Below your threshold, Affintra flags. Above it, Affintra can fix.

You control the weights and the auto-fix threshold per tenant.

LAPTOP-4471 · a.krause 97.2
{{ sig.name }} · {{ sig.desc }} {{ sig.weight }}
Platform

Everything between detection and done

Safe write-back pipeline

Dry-run first, always. Corrections go through review queues, per-tenant thresholds, batched Graph writes with rollback — and a full audit log of who changed what, when, and why.

Multi-tenant native

One console, all your tenants. Per-tenant weights, thresholds, and RBAC — built for MSPs and enterprise IT.

Explainable scores

Every verdict shows its evidence: sign-in counts, competing users, time windows. No black box.

Drift detection

Devices change hands. Affintra keeps watching sign-ins and re-scores continuously, so ownership never rots again.

API-first

Scores, verdicts, and remediation as REST endpoints. Wire it into your ITSM, your dashboards, your automations.

Product

Your tenant, scored and sorted

Triage by confidence, review the evidence, fix in bulk.

app.affintra.com / contoso.onmicrosoft.com
Mismatched · 312 Confirmed · 4,881 Low signal · 97 Fix 312 selected →
DeviceCurrent primaryDetected ownerScoreAction
{{ r.device }} {{ r.current }} {{ r.detected }} {{ r.score }} Review →
Try it

One click. That's the whole workflow.

This is what remediation feels like: review the evidence, approve, done. Intune is updated via Microsoft Graph, and the change is logged.

LAPTOP-2093 {{ demoStatus }}
Primary User{{ demoUser }}
Detected ownert.osei@corp.com
Confidence94.1 — D 38.2 · M 23.4 · C 18.9 · R 13.6
Evidence61 sign-ins / 30 days, 1 competing user
Dominance-weighted scoring·Graph API write-back·Dry-run mode·Audit trail·Drift re-scoring·Per-tenant thresholds·RBAC·Exclusion rules·
Dominance-weighted scoring·Graph API write-back·Dry-run mode·Audit trail·Drift re-scoring·Per-tenant thresholds·RBAC·Exclusion rules·
Integrations

Native to the Microsoft stack

Reads sign-in logs from Entra ID, device inventory from Intune, and writes corrections through Microsoft Graph. Nothing to install on devices.

Microsoft Intune Entra ID Microsoft Graph
Security

Least privilege, full transparency

Scoped Graph permissions, read-only by default, EU data residency, and encryption in transit and at rest. Write access is opt-in per tenant.

GDPR-ready SOC 2 (in progress) EU hosting SSO / Entra login

Retire the spreadsheet

The manual way vs. Affintra.

Manual process Affintra
{{ c.label }} {{ c.manual }} {{ c.affintra }}
We ran Affintra in dry-run mode on a Friday. By Monday we had 1,400 verified corrections queued — work that used to take a quarter.
Placeholder quote · Head of Modern Workplace, mid-size enterprise
For developers

Ownership as an API

Pull verdicts into your ITSM, trigger remediation from your own tooling, or subscribe to drift events via webhooks.

Read the docs →
GET /v1/devices/LAPTOP-2093/verdict
{
"detectedOwner": "t.osei@corp.com",
"confidence": 94.1,
"signals": { "dominance": 38.2, "margin": 23.4,
"consistency": 18.9, "recency": 13.6 },
"action": "auto_fix_eligible"
}
Pricing

A base fee per tenant, cents per device

Example pricing — final tiers TBD.

Most popular

{{ p.name }}

{{ p.tagline }}

{{ p.base }} /tenant/mo
+ {{ p.device }} per device/mo
{{ f }}
{{ p.cta }}

Live in 15 minutes

No agents. No scripts. One admin consent.

1
Consent
Admin grants scoped read permissions
2
Analyze
First full tenant score in minutes
3
Review & fix
Approve corrections, enable write-back when ready

Questions, answered

{{ q.a }}

Stop guessing who owns that laptop

Run a free dry-run analysis on your tenant. See your real mismatch rate in 15 minutes.

Book a demo Start free dry-run