Home
%3CLINGO-SUB%20id%3D%22lingo-sub-487193%22%20slang%3D%22en-US%22%3EGetting%20Started%20with%20Intune%20and%20Azure%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-487193%22%20slang%3D%22en-US%22%3E%3CP%3EOne%20of%20our%20engineers%20recently%20posted%20a%20great%20deep%20dive%20into%20how%20Microsoft%20uses%20Azure%20Log%20Analytics%20for%20our%20Intune%20environment.%20Sharing%20the%20intro%20here%20-%20if%20you're%20interested%20in%20how%20to%20get%20started%20with%20Azure%20Log%20Analytics%20and%20Intune%20head%20to%20the%20full%20article%20here%20-%26nbsp%3B%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FDevice-Management-in-Microsoft%2FMicrosoft-Intune-and-Azure-Log-Analytics%2Fba-p%2F463145%22%20target%3D%22_self%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FDevice-Management-in-Microsoft%2FMicrosoft-Intune-and-Azure-Log-Analytics%2Fba-p%2F463145.%3C%2FA%3E%20%26nbsp%3B%3C%2FP%3E%0A%3CDIV%20class%3D%22MessageSubjectIcons%20%22%20style%3D%22box-sizing%3A%20border-box%3B%20display%3A%20inline%3B%20font-family%3A%20%26amp%3Bquot%3B%22%3E%3CSPAN%20class%3D%22lia-message-unread%22%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22lia-message-body%20lia-component-message-view-widget-body%22%20id%3D%22messageBodyDisplay%22%20style%3D%22box-sizing%3A%20border-box%3B%20color%3A%20%23333333%3B%20font-family%3A%20%26amp%3Bquot%3B%20segoeui%26amp%3Bquot%3B%2C%26amp%3Bquot%3Blato%26amp%3Bquot%3B%2C%26amp%3Bquot%3Bhelvetica%20neue%26amp%3Bquot%3B%2Chelvetica%2Carial%2Csans-serif%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20letter-spacing%3A%20normal%3B%20line-height%3A%201.7142%3B%20margin-bottom%3A%2010px%3B%20orphans%3A%202%3B%20overflow%3A%20auto%3B%20overflow-wrap%3A%20break-word%3B%20text-align%3A%20left%3B%20text-decoration%3A%20none%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%3E%0A%3CDIV%20class%3D%22lia-message-body-content%22%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%20segoeui%26amp%3Bquot%3B%2C%26amp%3Bquot%3Blato%26amp%3Bquot%3B%2C%26amp%3Bquot%3Bhelvetica%20neue%26amp%3Bquot%3B%2Chelvetica%2Carial%2Csans-serif%3B%20font-size%3A%2016px%3B%20font-weight%3A%20300%3B%20line-height%3A%201.7142%3B%20margin-bottom%3A%2010px%3B%20overflow-wrap%3A%20break-word%3B%20white-space%3A%20normal%3B%22%3E%0A%3CP%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%20segoeui%26amp%3Bquot%3B%2C%26amp%3Bquot%3Blato%26amp%3Bquot%3B%2C%26amp%3Bquot%3Bhelvetica%20neue%26amp%3Bquot%3B%2Chelvetica%2Carial%2Csans-serif%3B%20margin-bottom%3A%200px%3B%20margin-left%3A%200px%3B%20margin-right%3A%200px%3B%20margin-top%3A%200px%3B%22%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E%3CEM%3ECross%20posting%20the%20blog's%20intro%3A%3C%2FEM%3E%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%20segoeui%26amp%3Bquot%3B%2C%26amp%3Bquot%3Blato%26amp%3Bquot%3B%2C%26amp%3Bquot%3Bhelvetica%20neue%26amp%3Bquot%3B%2Chelvetica%2Carial%2Csans-serif%3B%20margin-bottom%3A%200px%3B%20margin-left%3A%200px%3B%20margin-right%3A%200px%3B%20margin-top%3A%200px%3B%22%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3EMicrosoft%E2%80%99s%20production%20Intune%20tenant%20manages%20all%20MDM%20enrolled%20devices%20at%20the%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3Ecompany%2C%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E%26nbsp%3Band%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E%26nbsp%3Bwe%20have%20the%20need%20to%20closely%20monitor%20and%20analyze%20data%20that%20is%20coming%20from%20our%20Intune%20tenant%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E.%20In%20this%20post%20we%20will%20illustrate%20how%20we%20have%20configured%20diagnostic%20settings%20in%20Intune%20in%20order%20to%20send%20data%20to%20a%20Log%20Analytics%20workspace%20for%20our%20production%20Microsoft%20tenant%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E.%20This%26nbsp%3B%3C%2FSPAN%3E%3CA%20style%3D%22background-color%3A%20transparent%3B%20box-sizing%3A%20border-box%3B%20color%3A%20%23146cac%3B%20text-decoration%3A%20underline%3B%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Freview-logs-using-azure-monitor%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22none%22%3Enew%20feature%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-contrast%3D%22auto%22%3E%26nbsp%3Ballows%20customers%20to%20add%20Audit%20Logs%20and%20Operational%20Logs%20to%20a%20Log%20Analytics%20workspace%2C%20event%20hub%20or%20Azure%20storage%20account.%20This%20integration%20allows%20us%20to%20gain%20additional%20insights%20into%20data%20coming%20from%20the%20Intune%20service%20and%20the%20devices%20that%20we%20manage.%20In%20addition%2C%20it%20gives%20us%20a%20platform%20to%20build%20alerting%20%2F%20monitoring%20pipelines%2C%20reporting%2C%20and%20custom%20workflows%20based%20on%20data%20that%20we%20are%20receiving%20from%20our%20Intune%20tenant.%20By%20the%20end%20of%20this%20post%20we%20hope%20to%20demonstrate%20how%20to%20set%20up%20alerting%20%2F%20monitoring%20based%20on%20Intune%20data%20flowing%20into%20your%20Log%20Analytics%20workspace.%3C%2FSPAN%3E%3CSPAN%20style%3D%22box-sizing%3A%20border-box%3B%20font-family%3A%20%26amp%3Bquot%3B%22%20data-ccp-props%3D%22%7B%26quot%3B201341983%26quot%3B%3A0%2C%26quot%3B335559739%26quot%3B%3A160%2C%26quot%3B335559740%26quot%3B%3A259%7D%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-487193%22%20slang%3D%22en-US%22%3E%3CP%3EInterested%20in%20using%20Azure%20Log%20Analytics%20in%20your%20own%20Intune%20environment%3F%20Cross%20posting%20a%20how%20to%20get%20started%20guide%20on%20behalf%20of%20our%20engineering%20team%20that%20manages%20Microsoft's%20Intune%20environment.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-487193%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EEMS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%20Customer%20Success%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-562715%22%20slang%3D%22en-US%22%3ERe%3A%20Getting%20Started%20with%20Intune%20and%20Azure%20Log%20Analytics%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-562715%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E

One of our engineers recently posted a great deep dive into how Microsoft uses Azure Log Analytics for our Intune environment. Sharing the intro here - if you're interested in how to get started with Azure Log Analytics and Intune head to the full article here -  https://techcommunity.microsoft.com/t5/Device-Management-in-Microsoft/Microsoft-Intune-and-Azure-Log...  

 

Cross posting the blog's intro:

Microsoft’s production Intune tenant manages all MDM enrolled devices at the company, and we have the need to closely monitor and analyze data that is coming from our Intune tenant. In this post we will illustrate how we have configured diagnostic settings in Intune in order to send data to a Log Analytics workspace for our production Microsoft tenant. This new feature allows customers to add Audit Logs and Operational Logs to a Log Analytics workspace, event hub or Azure storage account. This integration allows us to gain additional insights into data coming from the Intune service and the devices that we manage. In addition, it gives us a platform to build alerting / monitoring pipelines, reporting, and custom workflows based on data that we are receiving from our Intune tenant. By the end of this post we hope to demonstrate how to set up alerting / monitoring based on Intune data flowing into your Log Analytics workspace. 

1 Comment
Frequent Visitor