KQL queries for Microsoft Intune Device Query

Device Queries(72)

Analyze Start Times and Run Durations of Processes

Assess CPU Physical Characteristics

Assigned Primary Tokens

BIOS Details

Blue Screen of Death

Certificates That Will Expire in the Next 90 days

Check if Device Restart Is Required

Check if TPM 2.0 is available

Command Lines Used to Start Processes

Detect CPU Overclocking

Detect Processes That Are Reading or Writing Significantly to Disk

Determine Which Users Are Running Which Processes

Event Log was Cleared

Failed User Account Login

Find All System Processes Related to Defender, Sense or Security

Find Devices with BitLocker Not Enabled

Find Devices with Multiple Physical Disks

Find Disk Information

Find Drivers That Don’t Have Associated Inf Files

Find Processes With High Memory Usage

Find Processes With Unusually High Thread or Handle Counts

Find Windows 11 Compatible Tpms

Flag Processes With Disproportionately Large Virtual Memory Usage

Group Drivers by Their Provider Name

Identify CPU Architecture Distribution

Identify CPU Configuration

Identify Devices with Outdated BIOS

Identify Processes That Are Heavily Using Disk Space

Identify Programs Set to Auto-Run at Startup

Identify Top Disk IO Processes

Identify Unexpected or Unknown Processes Running From Unusual Paths

Impact of Processes Over Time by Looking at How Long They Run

Intune MDM Device Certificate

List All CA Certificates

List All Process That Running Under NT Authority

List of Applications Crashes

Lookup Registry Keys Wildcard

Monitor CPU Performance and Health

Monitor Hosts File

Most frequently running Processes

Number of Events per Provider

Number of Signed and Unsigned Drivers

Old BIOS Versions

Overview Event Level Types for Windows Applications Events

Query Recent Windows System Event Logs

Search Recently Created Files at a Location

Service Start Failure

Show All Application Events

Show All Certificates That Are Not Stored in Localmachine

Show All Drivers That Are Not Signed

Show All Insecure Certificates

Show All Local Drives

Show all Local Groups on Device

Show All Self-Signed Certificates

Show Application Crashes

Show Application Hangs

Show Expired Certificates on Device

Show Failed Licence Activations

Show Latest Application Installations

Show Services That Have Started

Show Services That Have Stopped

Show Valid Certificates on Device

Successful User Account Login

System Age and Update Status Analysis

System Time Changed

Track the Usage of Specific Applications and How Often They Are Started

Track the Working Directories of Processes

User Added to Privileged Group

User Right Assigned

Windows App Crash Events Grouped by the App and Its Version

Windows Quick Fix Engineering Hot Fixes

Windows Update Installations

Select a query to view details