This repository contains a wide array of KQL Queries ready for you to easily copy, paste, and execute within Intune.
You can find more KQL Queries here -> KQLSearch.com
Device query allows you to quickly gain on-demand information about the state of your devices. When you enter a query on a selected device, Device query runs a query in real time. The data returned can then be used to respond to security threats, troubleshoot the device, or make business decisions.
Details:
Device Query -> Device Query
Data Platform Schema -> Data Platform Schema
- License:
- The Intune Advanced Analytics Add-on OR
- Microsoft Intune Suite
- The Windows Device has to be running and connected to the Internet.
- To use Device query on a device, the device must be enrolled in Endpoint Analytics.
- To use Device query, devices must be Intune managed and corporate owned.
- For a user to use Device query, you must assign the Managed Devices - Query permission to them.
Create a Issue or Pull Request if you want to add a new query or have a idea for one that could be useful for everyone.
Feel free to fork the repository and submit pull requests. For major changes, please open an issue first to discuss what you would like to change.