Lets admins run KQL in Advanced Analytics, either against near real-time data on a single device or, after deploying a properties catalog policy to Windows devices, against inventory gathered from many.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Device query in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Advanced Analytics
Adds device query, device scopes, a device timeline, anomaly detection, resource performance and battery health on top of endpoint analytics. It comes with the Intune Suite and with Intune Plan 2.
- Properties catalog
An Intune profile for Windows that gathers additional details about each machine's hardware and installed software. Querying many devices at once depends on that inventory being collected.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Copilot in Intune
Puts Security Copilot inside Intune's admin center. Admins can ask questions of their data in plain English, get policy and device summaries, and have device query KQL drafted for them; it consumes Security Copilot compute units, and scope tags and RBAC still apply.