The device list in the Intune admin center is fine for a quick look, but a weekly inventory, a stale-device list or a noncompliance report is easier to produce from a script. In this post I'll build that script step by step with the Microsoft Graph PowerShell SDK, then make it run unattended with a certificate.
Prerequisites#
- PowerShell 7 (recommended) or Windows PowerShell 5.1.
- The
Microsoft.Graph.DeviceManagementmodule, or the fullMicrosoft.GraphSDK. - The Graph permission
DeviceManagementManagedDevices.Read.All. It's the least-privileged permission for listing managed devices and exists as both a delegated and an application permission. - For interactive runs, an account with an Intune role that can read devices, such as Read Only Operator.
- An active Intune licence in the tenant, which the Intune Graph API requires.
Step-by-step#
1. Install the module and connect#
Install-Module Microsoft.Graph.DeviceManagement -Scope CurrentUser
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.Read.All" -NoWelcome
Get-MgContext | Select-Object Account, Scopes2. Export the inventory#
Ask only for the properties you need, and always add -All; without it you only get the first page of results.
$props = 'id','deviceName','userPrincipalName','operatingSystem','osVersion',
'complianceState','lastSyncDateTime','enrolledDateTime',
'managedDeviceOwnerType','serialNumber','model','manufacturer'
$devices = Get-MgDeviceManagementManagedDevice -All -Property $props
$devices |
Select-Object DeviceName, UserPrincipalName, OperatingSystem, OsVersion,
ComplianceState, LastSyncDateTime, EnrolledDateTime,
ManagedDeviceOwnerType, SerialNumber, Model, Manufacturer |
Export-Csv -Path .\IntuneDevices.csv -NoTypeInformation -Encoding UTF8Setting the encoding explicitly keeps non-Latin characters, such as Arabic user names, intact in the file. managedDeviceOwnerType tells you whether a device is company or personal, which is usually the first column managers ask about.
For a quick summary in the console before you open the CSV:
$devices | Group-Object OperatingSystem, ComplianceState -NoElement |
Sort-Object Count -Descending3. Find stale devices#
The inventory is already in memory, so filter it locally instead of calling Graph again:
$cutoff = (Get-Date).AddDays(-30)
$devices |
Where-Object { $_.LastSyncDateTime -lt $cutoff } |
Sort-Object LastSyncDateTime |
Select-Object DeviceName, UserPrincipalName, OperatingSystem, LastSyncDateTime |
Export-Csv -Path .\StaleDevices.csv -NoTypeInformation -Encoding UTF8If stale devices are all you need, Graph can filter on the server as well: lastSyncDateTime supports the lt and gt operators in -Filter.
4. List noncompliant devices#
complianceState supports eq and or in a server-side filter. Its values include compliant, noncompliant, conflict, error, inGracePeriod and configManager.
$nonCompliant = Get-MgDeviceManagementManagedDevice -All -Property $props `
-Filter "complianceState eq 'noncompliant'"
$nonCompliant | Group-Object OperatingSystem | Select-Object Name, Count5. Run it unattended with a certificate#
Scheduled runs shouldn't depend on someone signing in. Use app-only authentication:
- Register an app in Microsoft Entra ID and upload the public key of a certificate (
.cer,.pemor.crt). - Add the application permission
DeviceManagementManagedDevices.Read.Alland grant admin consent. - Install the certificate, with its private key, in the certificate store of the account that runs the scheduled task.
- Connect with the app's client ID, your tenant ID and the certificate thumbprint:
$connect = @{
ClientId = '00000000-0000-0000-0000-000000000000' # application (client) ID
TenantId = '11111111-1111-1111-1111-111111111111' # directory (tenant) ID
CertificateThumbprint = 'YOUR-CERTIFICATE-THUMBPRINT'
}
Connect-MgGraph @connect -NoWelcome
(Get-MgContext).AuthType # returns AppOnlyThe rest of the script runs unchanged; finish with Disconnect-MgGraph. A certificate is far safer than a client secret sitting in a script file.
6. Schedule it and keep a history#
Save the script, stamp each export with the date so you can compare weeks, and run it from Task Scheduler under the account that holds the certificate. Use full paths, because a scheduled task doesn't start in your script folder:
$stamp = Get-Date -Format 'yyyy-MM-dd'
$path = Join-Path $PSScriptRoot "IntuneDevices-$stamp.csv" # use as -Path in step 2
# Task Scheduler action
# Program: pwsh.exe
# Arguments: -NoProfile -NonInteractive -File C:\Scripts\Get-IntuneDeviceReport.ps1The module must be available to that account too: install it while signed in as that account, or use -Scope AllUsers from an elevated session. Keep the output folder access-controlled. The CSV holds user names and serial numbers, so treat it like any other personal data.
Verify#
Get-MgContextshows the scope you asked for, orAppOnlyfor the scheduled run.$devices.Countis in line with the total under Devices › All devices in the Intune admin center.- The CSV opens with one row per device, populated columns and sensible
LastSyncDateTimevalues.
Tips & gotchas#
- Paging:
-Allfollows every page for you.-PageSizeonly changes how many records each request returns. - Throttling: Graph answers bursts with HTTP 429 and a
Retry-Afterheader, and Microsoft's guidance notes the Graph SDKs already include retry handlers that honour it. The best protection is fewer calls: pull the list once and filter locally rather than querying device by device. - Unselected means empty: with
-Property, anything you didn't request comes back blank. A few properties are only populated when you get a single device rather than the list. - Time zones: Graph timestamps are in UTC, so allow for that when you choose cut-offs or share reports with colleagues elsewhere.
- SDK v2:
Select-MgProfileno longer exists. Beta cmdlets live in theMicrosoft.Graph.Betamodule, for exampleGet-MgBetaDeviceManagementManagedDevice.