Nov 23 2023 01:06 AM
Hello from Greece, i have a strange issue.
I cannot run any query in advanced hunting starting with deviceevents.
The device section is totally missing. Even if i type it it is marked red and i receive an error.
Is there any way i can update my schema?
I want the asr auditing events from my subscription.
Thank you!
Panos
Nov 28 2023 11:48 PM
Dec 08 2023 06:40 AM
@adiii @Panos83 Did you find a solution? I run into the same problem. The devices schema is missing. In a demo tenant I just created, the schema is visible and useable.
Our users have Microsoft 365 Business Premium licenses
The user that executes the query has an Office 365 E3 license (also assigned an MS 365 Business Premium license but that has no effect.)
There are 225 devices onboarded in Defender which report installed software, threat detections etc.
The devices were onboarded from Intune (MDM Enrolled)
Dec 11 2023 11:33 PM
SolutionDec 14 2023 01:34 AM
Jan 28 2024 08:39 PM
Dec 11 2023 11:33 PM
Solution