Event details

This AMA is designed for IT teams looking to cut through the noise and gain clearer insight into what’s really happening across their device estate.

You can’t secure or manage what you can’t fully see. As organizations support more users, more device types, and more ways of working, endpoint management has become increasingly complex. Windows, macOS, iOS, Android, personally-owned devices, frontline workers, remote teams: every layer adds new challenges when it comes to visibility, monitoring, compliance, and troubleshooting.

Come ready to talk through the sometimes messy realities of endpoint management in today's world. Let's talk about inconsistent reporting, missing signals, compliance blind spots, alert fatigue, cross-platform management, and the challenge of turning raw data into meaningful action. Want to know if your reporting is giving you the full picture? Curious where organizations typically lose visibility or struggle with enforcement at scale? Wondering how others are approaching analytics, monitoring, and troubleshooting across multiple platforms? Bring your toughest questions and compare notes directly with Microsoft experts and peers navigating the same challenges in Intune every day.

I'm in. How do I participate?

Sign in to the Tech Community, select Add to Calendar and Attend to receive event reminders. Post your questions (early and often!) in the Comments below.

 

This session is part of the Tech Community Live: Intune Edition. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event.

Heather_Poulsen
Updated Jun 19, 2026

17 Comments

  • Faisalits007's avatar
    Faisalits007
    Occasional Reader

    "What should we do if a Windows device shows as non-compliant in Intune, but there is no indicator explaining why? Should we proceed with formatting the machine, or is there another way to fix it?"

     

    • Mike-Danoski's avatar
      Mike-Danoski
      Icon for Microsoft rankMicrosoft

      It depends on why it is noncompliant and what measures you have in place to establish compliance. Formatting is quick but investigation is key to understanding why. It's also important to remember that the goal is secure access to corporate resources; blocking noncompliant devices until they are compliant and understanding what's going on with the device is a great practice.

  • Morgan-Jansen's avatar
    Morgan-Jansen
    Copper Contributor

    I am also wondering about the different information in the different views. Would you recommend we create custom dashboards?

    • David_Guyer's avatar
      David_Guyer
      Icon for Microsoft rankMicrosoft

      That is going to greatly depend on your scenarios.   

      Exporting data and creating custom dashboards is definitely an option and will allow you to join with your data that Intune doesn't have, and create custom views and dashboards.  Another benefit is you can store historical data, and generate those kind of reports.  However, this is more complicated to build and maintain, depending on your experience.

      In Intune, we are continuing to expand Explorer's capabilities and combined with Device Query you will be able to use or create custom queries that can become a good in-console solution, and we are exploring how we can continue to make this better.  These approaches will be simpler to create and will be hosted in the Intune console.

      Hopefully this gives you some insight how to think about choosing the best path for your scenario... you may find you use both, for different situations.

      -David Guyer
      Principal Product Manager - Intune

  • SCawed's avatar
    SCawed
    Copper Contributor

    Inactive devices in our tenant are deleted after 6 months,

    If we have a device that was lost or stolen. What is the best way to approach this scenario on laptops, ios devices, and android devices?

    Goal is to make the device unusable by whoever has it, like lock it on the user enrollment screen until a valid azure admin account is used to (re)enroll.

    • SCawed's avatar
      SCawed
      Copper Contributor

      Thanks for the responses. The tricky part is if device is auto-deleted after 6 months. We auto delete because inactive devices lowers our defender score, clutters the our portal, etc.

      Example, we had a lost iOS device suddenly resurface on intune after 1 year. It looks to have been factory reset using DFU mode. so they were able to get to the home screen, but not enroll so no access to company resources. I was able to place it on lost mode, but thief did another DFU reset (i think) and so I lost mode it again.

      It was whack a mole until they gave up. I've since created an iOS enrollment profile that places the device in single app mode (comp portal) when it auto pilots, and moved lost devices to this profile. That way thieves can not use it at all. 

      I was curious if this approach can be done on Windows devices, and Android.

    • Abigail_Stein's avatar
      Abigail_Stein
      Icon for Microsoft rankMicrosoft

      For Android devices, you'll also want to take a look at the available device actions. Depending on the scenario, actions such as Delete, Remote Lock, Retire, and Wipe may be appropriate.

    • David_Guyer's avatar
      David_Guyer
      Icon for Microsoft rankMicrosoft

      SCawed​ ,

      The place to look is at device actions.  Select the device under Devices, and then when the device page comes up the Overview page has a bar at the top of the actions you can take, which depends on the OS.  For example, for Windows, you can initiate a Wipe, and even unenroll the device from Intune, and there's additional options.  You can also rotate local admin passwords, do an autopilot reset, or try to locate the device... all potentially useful tools for lost devices.

      I do recommend testing these options before you need them to ensure you are familiar with how they work and their device impact.

      HTH,

      -David Guyer
      Principal Product Manager - Intune

  • C00kieMonster's avatar
    C00kieMonster
    Brass Contributor

    In SCCM, it's very easy to identify systems based off what specific apps they have installed what versions of apps are installed, etc. with clear understanding of how up-to-date the data is (as you mentioned with Device Query). Is there a way to get reporting like that from Intune specific to installed apps (regardless of whether the apps are installed/managed via Intune)? If so, is there a way to scope deployments based off those types of app-specific queries? Often times, with SCCM, we'll scope deployments based off what apps are missing, outdated, etc. 

    • David_Guyer's avatar
      David_Guyer
      Icon for Microsoft rankMicrosoft

      C00kieMonster​ ,

      We are in transition today, so there are two solutions in Intune today.   The older solution is Discovered Apps, which is reporting on the device and also under All App / Monitor, which shows the inventory of apps and which devices have those apps.

      The newer solution is only available today on a per-device basis.  Select a device, then All Apps, then the App Inventory tab.  This view shows the apps for that device, along with a lot more detail like last checked date, last updated, install location, and more.   We are working on bringing that data to an All Apps in my Tenant view, like the one I mentioned above.

      At this time, there isn't a way to use app inventory in policy targeting.  It's something we get lots of feedback about and are investigating. It turns out to be more complicated than it appears on the surface, while the benefits are quite clear.

      Hope this helps point you in the right direction... the data is available in Intune, may need a bit more data export and PowerShell scripting today to get the behaviors you are looking for, and we are moving to provide richer data, faster, and integrating it better into the console.

      -David Guyer
      Principal Product Manager - Intune (Apps & App Inventory)

  • C00kieMonster's avatar
    C00kieMonster
    Brass Contributor

    Is there a way in Intune to create a dynamic group for just Azure VMs? We have policies we only want applied to Azure VMs and none of our physical systems, but can't seem to find a way to accurately get a dynamic group to populate with only Azure VMs.

  • Welcome to today's AMA on gaining visibility and control across devices with Intune. Post your questions here in the comments!