INTUNE DEVICE QUERY

Find the right query,
fast.

Community-maintained KQL library for Microsoft Intune Device Query.

17 queries · 8 multi-device · 9 single-device
17 queries
Hardware Multi-Device

Battery Health Overview

Surfaces devices with degraded battery capacity across the entire fleet. Devices below 80% rated capacity are prime replacement candidates.

batteryhardwarehealth +2
Security Multi-Device

BitLocker Encryption Status

Shows the BitLocker encryption state for all system drives across the fleet. Flags unencrypted or partially encrypted volumes for compliance reporting and remediation.

bitlockerencryptionsecurity +3
Security Multi-Device

Windows Defender Antivirus Status

Surfaces devices where Windows Defender is not active or signature definitions are out of date. Results are ordered by oldest signature timestamp first.

defenderantivirussecurity +3
Storage Multi-Device

Devices with Low Disk Space

Finds devices where the system drive has less than 20% free space. Results are ordered by least available space to prioritise the most urgent cases.

diskstoragespace +3
Hardware Multi-Device

Hardware Specs Inventory

Fleet-wide hardware snapshot combining processor and memory data per device. Useful for lifecycle planning and identifying devices below minimum spec thresholds.

hardwareinventorycpu +5
Operating System Multi-Device

OS Build Version Distribution

Groups devices by Windows build number to show which OS versions are running across the fleet. Useful for patch compliance reporting and feature update planning.

oswindowsbuild +4
Security Multi-Device

TPM Version Compliance

Identifies which devices have TPM 2.0 enabled and activated. Essential for Windows 11 readiness assessments and security baseline enforcement.

tpmsecuritywindows11 +3
Patching Multi-Device

Missing Critical Windows Updates

Lists devices that are missing specific hotfixes from your compliance baseline. Replace the KB IDs in the requiredKBs list with the patches relevant to your organisation.

patchingupdateskb +4
Software Single-Device

Installed Applications

Lists all applications installed on the device including version, publisher, and install date. Useful for software inventory audits and licence reviews.

softwareapplicationsinventory +3
Security Single-Device

Certificates Expiring Within 12 Months

Lists certificates in the machine and user stores that will expire within the next 365 days. Sorted by soonest expiry first to surface urgent renewals.

certificatespkisecurity +4
Security Single-Device

Local User Accounts

Lists all local user accounts on the device including enabled state and last logon time. Useful for access audits and identifying stale or unexpected accounts.

usersaccountslocal +4
Network Single-Device

Network Adapters and IP Configuration

Shows all enabled network adapters with their assigned IP addresses, MAC addresses, and subnet configuration. Useful for network troubleshooting and asset tracking.

networkadapterip +4
Diagnostics Single-Device

Recent System and Application Errors

Pulls the 50 most recent Error and Critical events from the System and Application event logs. The first stop when diagnosing crashes, driver failures, or application errors.

eventserrorslogs +5
Performance Single-Device

Top Processes by Memory Usage

Shows the 20 processes consuming the most working-set memory on the device. The starting point for diagnosing performance issues and identifying memory leaks.

performancememoryprocesses +3
Software Single-Device

Startup Programs

Lists all programs configured to launch at user login or system startup. Useful for diagnosing slow boot times and auditing persistence mechanisms.

startupautorunboot +3
Hardware Single-Device

Connected USB and PnP Devices

Lists all Plug and Play devices currently visible to Windows, including USB peripherals, storage, and input devices. Useful for USB policy audits and hardware inventory.

usbpnpdevices +5
Diagnostics Single-Device

Stopped Auto-Start Services

Finds Windows services configured to start automatically that are currently stopped. These may indicate crashed or misconfigured services requiring investigation.

serviceswindowsdiagnostics +4