Get Azure Joined Device Information using PowerShell

%3CLINGO-SUB%20id%3D%22lingo-sub-823465%22%20slang%3D%22en-US%22%3EGet%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-823465%22%20slang%3D%22en-US%22%3E%3CP%3EI%20like%20to%20capture%20as%20much%20information%20on%20an%20Azure%20Join%20device%20using%20Powershell.%20Some%20of%20the%20information%20I%20looking%20to%20capture%20can%20be%20found%20in%20%22Intune%20for%20Education%22%20--%26gt%3B%20Device%20--%26gt%3B%20Go%20to%20Device%20Detail.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20limited%20to%20the%20information%20below.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20644px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F128596iABDD5085890DDB38%2Fimage-dimensions%2F644x174%3Fv%3D1.0%22%20width%3D%22644%22%20height%3D%22174%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tried%20using%20what%20GitHub%20had%20for%20Intune%20(%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fmicrosoft%2FIntune-PowerShell-SDK%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2Fmicrosoft%2FIntune-PowerShell-SDK%3C%2FA%3E)%20but%20couldn't%20get%20it%20to%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20would%20greatly%20be%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20You%2C%3C%2FP%3E%3CP%3E-Larry%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-823465%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EGraph%20API%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-824189%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-824189%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103153%22%20target%3D%22_blank%22%3E%40Larry%20Jones%3C%2FA%3E%26nbsp%3Bexcept%20for%20the%20Windows%20Defender%20status%2C%20the%20command%26nbsp%3BGet-IntuneManagedDevice%20will%20give%20you%20all%20the%20information%20in%20the%20device%20properties.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20kind%20of%20information%20are%20you%20looking%20for%20specifically%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-825238%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-825238%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F299305%22%20target%3D%22_blank%22%3E%40bjcls%3C%2FA%3E%26nbsp%3B%20thank%20you%20for%20responding.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3BSo%20far%20I%20was%20able%20get%20most%20the%20of%20information%20I'm%20looking%20for%20from%20an%20Azure%20Join%20device%20except%3A%3C%2FP%3E%3CUL%3E%3CLI%3ERecent%20Check-In%20(users%20that%20log%20into%20the%20device)%3C%2FLI%3E%3CLI%3Egroup%20memberships%20for%20device%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThank%20You%20again%20for%20your%20help.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Larry%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-825432%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-825432%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103153%22%20target%3D%22_blank%22%3E%40Larry%20Jones%3C%2FA%3E%26nbsp%3BI'm%20glad%20I%20could%20help!%3C%2FP%3E%3CP%3EIf%20you%20use%20the%20'beta'%20schema%20instead%20of%20'v1.0'%20(%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FMicrosoft%2FIntune-PowerShell-SDK%23known-issues-and-workarounds%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FMicrosoft%2FIntune-PowerShell-SDK%23known-issues-and-workarounds%3C%2FA%3E)%20and%20you%20run%20the%20same%20command%3A%26nbsp%3BGet-IntuneManagedDevice%20an%20extra%20value%3A%26nbsp%3BusersLoggedOn%20is%20shown.%3C%2FP%3E%3CPRE%3E%3CSPAN%20class%3D%22pl-c1%22%3EUpdate-MSGraphEnvironment%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22pl-k%22%3E-%3C%2FSPAN%3ESchemaVersion%20%3CSPAN%20class%3D%22pl-s%22%3E%3CSPAN%20class%3D%22pl-pds%22%3E'%3C%2FSPAN%3Ebeta%3CSPAN%20class%3D%22pl-pds%22%3E'%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3BThis%20value%20shows%20an%20ID%20that%20you%20can%20lookup%20with%20the%20command%3A%26nbsp%3BGet-AzureADUser%20-ObjectId%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20your%20second%20question%20I've%20used%20a%20Graph%20API%20call%2C%20because%20I%20didn't%20find%20a%20command%20in%20this%20module%3A%3C%2FP%3E%3CP%3E%3CEM%3E%24apiUrl%20%3D%20%22%3CA%20href%3D%22https%3A%2F%2Fgraph.microsoft.com%2Fbeta%2Fdevices%2F%24Deviceid%2Fmemberof%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgraph.microsoft.com%2Fbeta%2Fdevices%2F%24Deviceid%2Fmemberof%3C%2FA%3E%22%3C%2FEM%3E%3CBR%20%2F%3E%3CEM%3E%24Data%20%3D%20Invoke-RestMethod%20-Headers%20%40%7BAuthorization%20%3D%20%22Bearer%20%24(%24Tokenresponse.access_token)%22%20%7D%20-Uri%20%24apiUrl%20-Method%20Get%3C%2FEM%3E%3CBR%20%2F%3E%3CEM%3E%24DeviceGroups%20%3D%20(%24Data%20%7C%20select-object%20Value).Value%3C%2FEM%3E%3C%2FP%3E%3CP%3EOr%20you%20could%20check%20the%20members%20of%20a%20group%3A%26nbsp%3BGet-AADGroupMember%20instead%20of%20the%20group%20membership.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-825454%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-825454%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F299305%22%20target%3D%22_blank%22%3E%40bjcls%3C%2FA%3E%26nbsp%3B%20again%20thank%20you%20very%20much.....%20it's%20obvious%20I'm%20new%20to%20using%20graph.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EShould%20i%20run%20%22Update-MSGraphEnvironment%20-SchemaVersion%20'beta'%22%20after%20I%20run%20Connect-MSGraph%3F%20Also%2C%20will%20this%20update%20command%20make%20any%20changes%20to%20my%20Tenant%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20You%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Larry%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-825972%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-825972%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103153%22%20target%3D%22_blank%22%3E%40Larry%20Jones%3C%2FA%3E%26nbsp%3BYou%20can%20switch%20between%20v1.0%20and%20beta%20without%20any%20issues%20and%20it%20doesn't%20matter%20when%20you%20run%20the%20command.%20After%20you%20ran%20the%20command%2C%20you%20get%20a%20message%20telling%20you%20to%20run%20the%3A%20Connect-MSGraph%3A%20%3CEM%3E%22WARNING%3A%20Call%20the%20'Connect-MSGraph'%20cmdlet%20to%20use%20the%20updated%20environment%20parameters.%22%3C%2FEM%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESwitching%20to%20'beta'%20has%20no%20impact%20on%20your%20tenant%2C%20it%20just%20switches%20to%20the%20beta%20version%20of%20Graph%20API%20where%20you%20have%20more%20options%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fgraph%2Fapi%2Foverview%3Fview%3Dgraph-rest-1.0%23other-api-versions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fgraph%2Fapi%2Foverview%3Fview%3Dgraph-rest-1.0%23other-api-versions%3C%2FA%3E%3C%2FP%3E%3CP%3EAlso%20check%20out%20this%20website%20from%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F379303%22%20target%3D%22_blank%22%3E%40TheLazyAdministrator%3C%2FA%3E%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.thelazyadministrator.com%2F2019%2F07%2F22%2Fconnect-and-navigate-the-microsoft-graph-api-with-powershell%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.thelazyadministrator.com%2F2019%2F07%2F22%2Fconnect-and-navigate-the-microsoft-graph-api-with-powershell%2F%3C%2FA%3EIt%20helped%20me%20a%20lot%20on%20how%20to%20connect%20to%20Graph%20API%20using%20powershell%2C%20that%20way%20you%20have%20even%20more%20options%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-834346%22%20slang%3D%22en-US%22%3ERe%3A%20Get%20Azure%20Joined%20Device%20Information%20using%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-834346%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F299305%22%20target%3D%22_blank%22%3E%40bjcls%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F103153%22%20target%3D%22_blank%22%3E%40Larry%20Jones%3C%2FA%3E%26nbsp%3BIf%20you%20don't%20find%20the%20commands%20you%20are%20looking%20for%20in%20the%20Microsoft.Graph.Intune%20module%20you%20could%20just%20run%20Invoke-MSGraphRequest%20and%20use%20the%20complete%20MS%20Graph%20API%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20have%20already%20connected%20with%20Connect-MSGraph%20you%20don't%20have%20to%20spend%20multiple%20code%20lines%20getting%20an%20auth%20token%20and%20creating%20the%20correct%20header.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

I like to capture as much information on an Azure Join device using Powershell. Some of the information I looking to capture can be found in "Intune for Education" --> Device --> Go to Device Detail. 

 

Not limited to the information below.

clipboard_image_0.png

 

I tried using what GitHub had for Intune (https://github.com/microsoft/Intune-PowerShell-SDK) but couldn't get it to work.

 

Any help would greatly be appreciated.

 

Thank You,

-Larry 

6 Replies

@Larry Jones except for the Windows Defender status, the command Get-IntuneManagedDevice will give you all the information in the device properties.

 

What kind of information are you looking for specifically?

 

@bjcls  thank you for responding. 

 

 So far I was able get most the of information I'm looking for from an Azure Join device except:

  • Recent Check-In (users that log into the device)
  • group memberships for device

Thank You again for your help.

 

-Larry

@Larry Jones I'm glad I could help!

If you use the 'beta' schema instead of 'v1.0' (https://github.com/Microsoft/Intune-PowerShell-SDK#known-issues-and-workarounds) and you run the same command: Get-IntuneManagedDevice an extra value: usersLoggedOn is shown.

Update-MSGraphEnvironment -SchemaVersion 'beta'

 This value shows an ID that you can lookup with the command: Get-AzureADUser -ObjectId

 

For your second question I've used a Graph API call, because I didn't find a command in this module:

$apiUrl = "https://graph.microsoft.com/beta/devices/$Deviceid/memberof"
$Data = Invoke-RestMethod -Headers @{Authorization = "Bearer $($Tokenresponse.access_token)" } -Uri $apiUrl -Method Get
$DeviceGroups = ($Data | select-object Value).Value

Or you could check the members of a group: Get-AADGroupMember instead of the group membership.

@bjcls  again thank you very much..... it's obvious I'm new to using graph.  

 

Should i run "Update-MSGraphEnvironment -SchemaVersion 'beta'" after I run Connect-MSGraph? Also, will this update command make any changes to my Tenant?

 

Thank You,

 

-Larry

@Larry Jones You can switch between v1.0 and beta without any issues and it doesn't matter when you run the command. After you ran the command, you get a message telling you to run the: Connect-MSGraph: "WARNING: Call the 'Connect-MSGraph' cmdlet to use the updated environment parameters." 

Switching to 'beta' has no impact on your tenant, it just switches to the beta version of Graph API where you have more options: https://docs.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0#other-api-versions

Also check out this website from @TheLazyAdministratorhttps://www.thelazyadministrator.com/2019/07/22/connect-and-navigate-the-microsoft-graph-api-with-po... It helped me a lot on how to connect to Graph API using powershell, that way you have even more options ;)

@bjcls @Larry Jones If you don't find the commands you are looking for in the Microsoft.Graph.Intune module you could just run Invoke-MSGraphRequest and use the complete MS Graph API

 

If you have already connected with Connect-MSGraph you don't have to spend multiple code lines getting an auth token and creating the correct header.