Identify devices running software using Defender ATP

Occasional Contributor

I'm trying to identify if we can (easily) remove a software from our default installation package in our company. I would like to know how many are using the software to determine the impact this would have for our end users. It is not feasible in this case to do a survey or similar. 

I was thinking of using advanced threat hunting query to identify how many users have used the software (in the last month or so). Any ideas for how to implement this query would be appreciated!



2 Replies



Have you seen this article?


Also, do you have Intune or System Center in your environment?  Although MDATP has some capabilities to do Software Management, usually, these are the services that you would use for this type of request.  SCCM can interconnect with Intune in order to do co-manage so you can control both on-prem and cloud joined devices.

You may be able to do this as well using PowerShell connecting to the Microsoft Graph Security API.



@Gladys Rodriguez 

Thank you for your reply. I will check out the tips you provided.