How to Use Device Query in Intune
By Get Rubix
Summary
Topics Covered
- Highlights from 00:00-02:50
- Highlights from 02:36-04:56
- Highlights from 04:54-07:13
- Highlights from 07:09-09:16
- Highlights from 09:13-11:07
Full Transcript
So, I'm helping my friend, you know, where we're picking out like an SD card or something on on Amazon and found one he liked. Okay, great. It wasn't stock
he liked. Okay, great. It wasn't stock and you know how they got the same-day delivery or the overnight delivery. They
had the one-hour delivery available.
That's my absolute favorite. He said,
"No, I don't need it that fast. I'm fine
with the overnight."
What are you talking about? It's free.
You're going to You're going to wait overnight just because you don't need it as as as fast I don't understand that.
And what's even better is now this this guy who's bringing it over to you you're in his life. He's part of your life now. His day is different. His
life now. His day is different. His
plans changed. It It's a whole He's going to come to you now with this stupid little SD card. You don't You're not interested in that. You don't want that? Steve Watermeyer from getrubix.com
that? Steve Watermeyer from getrubix.com and we're going continue with our Intune sweet series now that the capabilities are available in E5 and some are in E3.
Speaking of the ones that are in E3, today we're going to take a look at advanced analytics and device query. I
don't understand how you don't want them to bring it as fast as possible. Yeah, I
get stuff delivered pretty quickly, but it ends up just sitting in the box for a week by my front door, so I don't know.
So, the thing we always hear the most complaints about within tune is the reporting, getting device information.
It's like a non-stop complaint department and finally, now that this is included, I feel like the core Intune product is going to offer something better. Advanced analytics builds on
better. Advanced analytics builds on endpoint analytics. So, if we go to
endpoint analytics. So, if we go to reports, in addition to what you already get in endpoint analytics, advanced analytics gives you a resource performance score. Uh this shows you
performance score. Uh this shows you CPU, RAM issues, things like that. You
get an anomaly report. This is really effective for uh changes in device health or regressions after certain configuration changes. And you can see
configuration changes. And you can see those stats on individual devices. So if
we're looking at a specific PC, we can see its startup performance compared to other devices, what's actually slowing it down, time to sign-in screen, group
policy, OS restart history. But that's
just one part of the story with advanced analytics. What we're focusing on today
analytics. What we're focusing on today goes a whole lot deeper. So probably the best thing that the advanced analytics feature gives us is the ability to query devices for information. So I'm going to
go to my Windows devices. I'm going to look up my device here in the tenant, and we're going to go down to uh device query. So these are all the available
query. So these are all the available properties you can query and use KQL.
And let's do something simple. Let's do
Windows service uh where the display name contains uh let's say anything.
And then I want to bring back the display name, service name, state, and start mode.
And let's hit run.
All right. So this brought me back pretty much almost near real time from the device. There was no editing there
the device. There was no editing there cuz I wanted to take a sip of my coffee.
Uh the Intune management extension service, that's the name, it's running, and it's auto mode.
Uh that's pretty good. Now let's check out another service. I'm going to type WinRM.
Uh I don't remember. That should just con- I don't know if that's display name or not.
Might be.
Yeah, that's the service name.
Let's try that. Let's change the query a little bit.
All right. So that gives us the Windows remote Management Service. It is stopped and the start mode is in manual.
Um so if I'm getting real-time information from the device and then what kind of information, you know, again, look at everything on the side here you can grab. You can grab Windows events. So let's say for example, I
events. So let's say for example, I wanted to get uh real-time event information. Windows
event, I got to give it the log name.
And I have to give it a look back time.
Let's say 7 days.
There's going to be quite a bit of information there. So I'm going to
information there. So I'm going to narrow down where message contains uh installation
completed successfully.
You know, get some See if there's any apps that have been installed and I'm going to project the event ID, the message, and the log date
and time. Let's run that.
and time. Let's run that.
Try to drink my coffee.
Mhm.
Barely enough time to drink my coffee.
So yeah, I can see all the apps that have installed successfully in the last few days.
Um and if I wanted to bring more information, so if I want to bring everything over and I I'll just get rid of the projection line cuz I'll bring back everything.
So now we could see uh let's see here everything. The event ID, information
everything. The event ID, information level, log date, the message, the provider name, the user account.
So this is pretty incredible for anyone who's complained that they can't see enough device information in Intune. I
think that's pretty good and you know, for anyone who's complained that they're not seeing enough device information in Intune, that that's not only a lot of information, it's fairly quickly. So
they've done a good job with this. But
if you're not seeing this and you have the license, don't worry, it's not broken. We just have to deploy the
broken. We just have to deploy the policy. Well, what policy is that? So,
policy. Well, what policy is that? So,
you want to make sure you have a properties catalog policy enabled. So,
if I go to Windows configuration, I'm going to create a new policy.
My platform is Windows 10 and later, obviously. Can we just call that Windows
obviously. Can we just call that Windows or Windows 11? But then eventually it'll be a 12, so maybe just Windows.
For profile type, we're going to choose properties catalog. Now, if you recall
properties catalog. Now, if you recall when we covered the app inventory, uh we had to use this and turn on the application data collection.
Um honestly, I I I don't think there's a reason to not check a certain one, so just select every single property in here.
And you'll be fine. It'll be okay.
There's nothing wrong with this. They're
not going to charge you a per the the feature. If you have something against
feature. If you have something against AI, you can you can leave that off, I guess, but just select the whole thing.
You see this stuff refreshes every 24 hours, so the data is It does a pretty accurate collection.
And just assign this to all devices. I
showed you what device query does, how to turn it on, but I know what you're going to say, "Steve, that's helpful if I know of a device that has a problem."
But what if I'm looking across my entire fleet? Well, they got you covered there
fleet? Well, they got you covered there because you can query your entire fleet.
So, back in Intune, if I go to the devices menu, right up top, I'm going to see a device query. So, this is essentially the same look, but there's some different stats here. Let's say I want to find all the devices that don't
have encrypted disks. That's kind of important, right? If I'm asked that on
important, right? If I'm asked that on the fly, maybe on a Monday morning, that's the kind of thing that would happen, right? Where the protection
happen, right? Where the protection status is not equal to protected.
And then bring back Uh actually, I'm going to join that to the logical drive. So, I want all the drive information. Let's run that.
drive information. Let's run that.
Now, this is going to run across the entire fleet. Now, my entire fleet is
entire fleet. Now, my entire fleet is about three virtual machines.
Ooh, okay. So,
oh, that's no good. I was hoping this would come I was actually hoping this would come back, "Hey, no, don't worry about it. Everything's protected. You're
about it. Everything's protected. You're
It looks good." I was going to have to show you a different query, but apparently I got problems here. So,
um you can see my uh okay, a lot of these are my Windows 365 PC sessions. I could see which drive it
PC sessions. I could see which drive it is. It's the D drive, the protection
is. It's the D drive, the protection status, encryption is zero, when it was last modified. Look at all this data I'm
last modified. Look at all this data I'm getting back across the, you know, uh the across the fleet. Now, what's really important about this is what if I want
to address this? I have the information, but I want to do something with it. I
can now add all items to a group. So, I
made that query. I could add these to a group. I could, you know, go to enter in
group. I could, you know, go to enter in another tab and make the group and then put them here. So, so I don't have to just let that query go as a one-time thing. I could save that. Yes, I'm aware
thing. I could save that. Yes, I'm aware I should be able to make the group right there. That would be a great feature. We
there. That would be a great feature. We
can't do it yet. You know, baby steps.
Well, what do you want? All right, so let's do one more. I want to get my lowest spec machines because I'm looking to do a a device refresh.
Who doesn't like a new laptop, am I right?
Manufacturer architecture core count. All right.
core count. All right.
Now, I want to order this by core count ascending.
And I want to see the I'll see the top five results.
All right, so these are my top five losers, we'll call them. They have the least amount of core counts. And uh
maybe uh I'll add these to a refresh group because now I know that these are the devices that needed the most.
Obviously, I can extend this number and get back 10, 20, whatever I want.
Depends on your fleet. But I'll [snorts] be able to pull that in real time. And
here's the thing with multi-device query. It the device doesn't have to be
query. It the device doesn't have to be online. It'll look at the last data
online. It'll look at the last data collected within 24 hours. So think
about what we have now. We have device query on a single device. That's near
real time, 3 to 5 seconds. I you saw it I couldn't even sip my coffee. I can
pull information when a user's having a problem. Multi-device query, the device
problem. Multi-device query, the device doesn't have to be online. I can
assemble groups of device with certain problems. If I get asked about finding devices that aren't encrypted, if I get asked about things due for a refresh, I can go pull that now across the fleet without pulling in a group. And yes, I
can take those results and add them to a group. So this is a tremendous step and
group. So this is a tremendous step and I think for this being one of the biggest complaints about Intune, and now it's here included in the licensing. Again, this is an E3 and E5.
licensing. Again, this is an E3 and E5.
Big win. Um hard to see the downside with this. So let me know your thoughts
with this. So let me know your thoughts if you've been using it. There's some
more parts to advanced analytics that we'll cover in the future, but I would say this is the best place to get started. Let me know your thoughts, jump
started. Let me know your thoughts, jump in the Discord, and we'll be seeing you.
Keep moving. Keep moving.
It's [music] all in for the modern workplace.
Where I am a great employee.
[music] Keep moving.
Loading video analysis...