Knowledge base / Asset Management / How it works
How it works
Asset Management is a single SharePoint Framework (SPFx) web part. It runs in each user's browser, inside a SharePoint page. Data is read and written only through SharePoint in your tenant; emails and scheduled work run in Power Automate flows; only device sync touches Microsoft Graph.
Asset Management web part
Runs in the user's browser on a SharePoint page, as the signed-in user. Covers the full browser window.
SharePoint Online: your asset site
Hidden lists with the prefix AM_: assets, assignments, acknowledgements, requests, maintenance, audits, contracts, devices, outbox, reminder queue, notifications, staff and settings.
Power Automate: three flows
Email (from the team mailbox), reminders & digest (scheduled), and daily device sync — all running under one service account.
Microsoft Graph: devices only
Intune managed devices and Entra ID devices, read-only. Browser sync uses delegated rights; the daily flow uses an app registration.
Key ideas
- Delegated access only. The app always acts as the person using it. It can never read or do more than that person could in Microsoft 365.
- Status kinds drive logic, never titles. Every status belongs to one of six fixed kinds — Available, Assigned, Maintenance, Retired, Disposed, Lost. A status's kind can never change after creation.
- Employees never edit the register. Receipt confirmations and requests go into their own lists; an asset manager's page records them after checking SharePoint's Created By and version history.
- Background work without a server. Due reminders, receipt confirmations and device processing run in an asset manager's open page; when nobody is online, the Power Automate flows do the same work. Every item is claimed first, so nothing is done twice.
- Schema as code. The app knows exactly which lists and columns it needs. Setup creates them. After an upgrade, the first visit by a site owner checks them and adds anything missing. Existing data is never removed.
- Live updates. Open pages ask SharePoint every few seconds what changed, so a new request, approval or assignment appears without a reload.
Microsoft Graph permissions
The package asks for two delegated permissions, only needed for the “Sync now” device sync from the browser. A SharePoint or global administrator approves them once, in the SharePoint admin center under Advanced › API access.
| Permission | Used for | If it is not approved |
|---|---|---|
| DeviceManagementManagedDevices.Read.All | Reading Intune managed devices for “Sync now” | Browser sync cannot run. The daily flow (app registration) still works. |
| Device.Read.All | Reading Entra ID devices for “Sync now” | Entra ID devices are skipped in the browser sync. |