Admin Guide

Configuring and running ntools-uem.

Two purpose-built desktop tools cover everything day to day: nTools - UEM Config Manager for defining what gets delivered and to whom, and Log Viewer for keeping an eye on the fleet.

Looking for the end-user side instead? See the User Guide.

1. The building blocks

Three concepts cover almost everything you'll do.

📁

Configuration Items

The individual things you want delivered — a script, a registry import, a file, an extracted archive, or a shortcut. Each has a name, a type, and a priority that controls run order.

👥

Assignments

The mapping between a Configuration Item and an Entra ID group — the groups you already manage, nothing new to maintain — with a target of that group's Users or its Devices.

📊

Log Viewer

Find any managed PC, read its real logs, and request an on-demand refresh — without remoting into the machine.

2. The five Configuration Item types

3. Assigning items with Entra ID groups

Every Configuration Item is assigned to one or more Entra ID groups, targeting either the Users in that group or the Devices in it. An item that runs as the signed-in user can target either — a user group applies wherever that person signs in, a device group applies to whoever signs in on those machines. An item that runs as the system can only target device groups, and nTools - UEM Config Manager enforces that outright, since there's no signed-in user for a machine-scoped item to check against. It's a small guardrail that stops an assignment from being created that could never actually apply.

4. Managing items in nTools - UEM Config Manager

One list, full visibility

Every item — including disabled ones, shown dimmed — with its type, priority, and how many groups it's assigned to. Filter by name or type; select one to see its full assignment list.

Safe edits

Editing a live item (one already assigned somewhere) asks first if the change could affect machines. Deleting is refused outright while any assignment still references it.

A built-in file library

Browse every file that's actually been uploaded, matched against current items — anything no item references any more is clearly marked, so cleanup is easy.

5. Monitoring and refreshing in Log Viewer

6. How syncing actually works

A background sync runs automatically every 30 minutes on every managed device — no admin action needed. On top of that, two on-demand paths exist: a user can trigger their own refresh from the tray icon (see the User Guide), or an admin can request one remotely from Log Viewer. Either way, the device applies the latest assignments, mirrors the config files it now needs, and uploads its logs — and because assignments and config are cached locally, a device that's temporarily offline just keeps running its last known-good configuration until it reconnects.

Questions about setting this up in your environment?

We're happy to walk through configuration, assignment design, or migration from your current tooling.

Get in touch