Battery Health Overview
Surfaces devices with degraded battery capacity across the entire fleet. Devices below 80% rated capacity are prime replacement candidates.
Community-maintained KQL library for Microsoft Intune Device Query.
Surfaces devices with degraded battery capacity across the entire fleet. Devices below 80% rated capacity are prime replacement candidates.
Shows the BitLocker encryption state for all system drives across the fleet. Flags unencrypted or partially encrypted volumes for compliance reporting and remediation.
Surfaces devices where Windows Defender is not active or signature definitions are out of date. Results are ordered by oldest signature timestamp first.
Finds devices where the system drive has less than 20% free space. Results are ordered by least available space to prioritise the most urgent cases.
Fleet-wide hardware snapshot combining processor and memory data per device. Useful for lifecycle planning and identifying devices below minimum spec thresholds.
Groups devices by Windows build number to show which OS versions are running across the fleet. Useful for patch compliance reporting and feature update planning.
Identifies which devices have TPM 2.0 enabled and activated. Essential for Windows 11 readiness assessments and security baseline enforcement.
Lists devices that are missing specific hotfixes from your compliance baseline. Replace the KB IDs in the requiredKBs list with the patches relevant to your organisation.
Lists all applications installed on the device including version, publisher, and install date. Useful for software inventory audits and licence reviews.
Lists certificates in the machine and user stores that will expire within the next 365 days. Sorted by soonest expiry first to surface urgent renewals.
Lists all local user accounts on the device including enabled state and last logon time. Useful for access audits and identifying stale or unexpected accounts.
Shows all enabled network adapters with their assigned IP addresses, MAC addresses, and subnet configuration. Useful for network troubleshooting and asset tracking.
Pulls the 50 most recent Error and Critical events from the System and Application event logs. The first stop when diagnosing crashes, driver failures, or application errors.
Shows the 20 processes consuming the most working-set memory on the device. The starting point for diagnosing performance issues and identifying memory leaks.
Lists all programs configured to launch at user login or system startup. Useful for diagnosing slow boot times and auditing persistence mechanisms.
Lists all Plug and Play devices currently visible to Windows, including USB peripherals, storage, and input devices. Useful for USB policy audits and hardware inventory.
Finds Windows services configured to start automatically that are currently stopped. These may indicate crashed or misconfigured services requiring investigation.
No queries match your search.
Try different keywords or clear the filters.