Are incorrectly enrolled devices able to be queried in Advanced Hunting?

Medea 0 Reputation points
2024-05-25T14:51:12.4333333+00:00

Hi,

I am using Advanced Hunting to perform some auditing. I expected some devices to return results, but they are not; and the number of results when I search for all devices is way lower than expected for my queries.

After checking the different IDs, I am noticing that only the devices correctly registered in Intune (i.e. not "pending" on Entra) are appearing in the reports.

The devices are onboarded in Defender and their "last seen" property seems correct.

So my question is: is that a simple coincidence, or can I have results for queries only from properly registered devices? (I cannot do testing as I can't get a "pending" device on purpose...)

Thank you!

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,654 questions
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 10,580 Reputation points Microsoft Vendor
    2024-05-27T07:14:52.8133333+00:00

    @Medea, Thanks for posting in Q&A.

    Since the data is collected by Defender and I am not familiar with Defender, are you using Defender for endpoint or Defender for Cloud? Please tag the corresponding one or contact the corresponding support for help.

    https://video2.skills-academy.com/en-us/defender-endpoint/contact-support

    https://video2.skills-academy.com/en-us/defender-cloud-apps/support-and-ts

    Thanks for your kind understanding.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.