Intune reports and properties available using Graph API

Microsoft Intune provides many reports in the console that can be exported using Graph APIs. Microsoft Graph is a RESTful web API that enables you to access Microsoft Cloud service resources. To export Intune reports, you must use the Microsoft Graph API to make a set of HTTP calls. For more information about , see Export Intune reports using Graph APIs.

Note

Intune reports that have been migrated to a new Intune reporting infrastructure, will be available for export from a single top-level export Graph API.

For more information about making REST API calls, including tools for interacting with Microsoft Graph, see Use the Microsoft Graph API.

Microsoft Endpoint Manager will export reports using the following Microsoft Graph API endpoint:

https://graph.microsoft.com/beta/deviceManagement/reports/exportJobs

The following table contains the possible values for the reportName parameter. These are the currently available reports for export.

ReportName (Export Parameter) Associated Report in Microsoft Endpoint Manager
DeviceCompliance Device Compliance Org
DeviceNonCompliance Non-compliant devices
Devices All devices list
DetectedAppsAggregate Detected Apps report
FeatureUpdatePolicyFailuresAggregate Under Devices > Monitor > Failure for feature updates
DeviceFailuresByFeatureUpdatePolicy Under Devices > Monitor > Failure for feature updates > click on error
FeatureUpdateDeviceState Under Reports > Window Updates > Reports > Windows Feature Update Report
UnhealthyDefenderAgents Under Endpoint Security > Antivirus > Win10 Unhealthy Endpoints
DefenderAgents Under Reports > MicrosoftDefender > Reports > Agent Status
ActiveMalware Under Endpoint Security > Antivirus > Win10 detected malware
Malware Under Reports > MicrosoftDefender > Reports > Detected malware
AllAppsList Under Apps > All Apps
AppInstallStatusAggregate Under Apps > Monitor > App install status
DeviceInstallStatusByApp Under Apps > All Apps > Select an individual app
UserInstallStatusAggregateByApp Under Apps > All Apps > Select an individual app

Each of the listed reports is described below.

AllAppsList

The following table contains the possible output when calling the AllAppsList report:

Available properties
AppIdentifier
Name
Publisher
Platform
Status
Type
Version
Description
Developer
FeaturedApp
Notes
Owner
DateCreated
LastModified
ExpirationDate
MoreInformationURL
PrivacyInformationURL
StoreURL
Assigned

There are no filters for this report.

AppInstallStatusAggregate

The following table contains the possible output when calling the AppInstallStatusAggregate report:

Available properties
ApplicationId
DisplayName
Publisher
Platform
Platform_loc
AppVersion
InstalledDeviceCount
InstalledUserCount
FailedDeviceCount
FailedUserCount
PendingInstallDeviceCount
PendingInstallUserCount
NotApplicableDeviceCount
NotApplicableUserCount
NotInstalledDeviceCount
NotInstalledUserCount
FailedDevicePercentage

You can choose to filter the AppInstallStatusAggregate report's output based on the following columns:

  • Platform
  • FailedDevicePercentage

DeviceInstallStatusByApp

The following table contains the possible output when calling the DeviceInstallStatusByApp report:

Available properties
DeviceName
UserPrincipalName
Platform
AppVersion
DeviceId
AssignmentFilterIdsExist
LastModifiedDateTime
AppInstallState
AppInstallState_loc
AppInstallStateDetails
AppInstallStateDetails_loc
HexErrorCode

You can choose to filter the AppInstallStatusAggregate report's output based on the following columns:

  • ApplicationId
  • AppInstallState
  • HexErrorCode (Used as ErrorCode)

UserInstallStatusAggregateByApp

The following table contains the possible output when calling the UserInstallStatusAggregateByApp report:

Available properties
UserName
UserPrincipalName
FailedCount
InstalledCount
PendingInstallCount
NotInstalledCount
NotApplicableCount

There are no filters for this report.

DeviceCompliance report

The following table contains the possible output when calling the DeviceCompliance report:

Available properties
DeviceId
IntuneDeviceId
AadDeviceId
DeviceName
DeviceType
OSDescription
OSVersion
OwnerType
LastContact
InGracePeriodUntil
IMEI
SerialNumber
ManagementAgents
PrimaryUser
UserId
UPN
UserEmail
UserName
DeviceHealthThreatLevel
RetireAfterDatetime
PartnerDeviceId
ComplianceState
OS

You can choose to filter the DeviceCompliance report's output based on the following columns:

  • ComplianceState
  • OS
  • OwnerType
  • DeviceType

DeviceNonCompliance report

The following table contains the possible output when calling the DeviceNonCompliance report:

Available properties
DeviceId
IntuneDeviceId
AadDeviceId
DeviceName
DeviceType
OSDescription
OSVersion
OwnerType
LastContact
InGracePeriodUntil
IMEI
SerialNumber
ManagementAgents
PrimaryUser
UserId
UPN
UserEmail
UserName
DeviceHealthThreatLevel
RetireAfterDatetime
PartnerDeviceId
ComplianceState
OS

You can choose to filter the DeviceNonCompliance report's output based on the following columns:

  • OS
  • OwnerType
  • DeviceType
  • UserId
  • ComplianceState

Devices report

The following table contains the possible output when calling the Devices report:

Available properties
DeviceId
DeviceName
DeviceType
ClientRegistrationStatus
OwnerType
CreatedDate
LastContact
ManagementAgents
ManagementState
ReferenceId
CategoryId
EnrollmentType
CertExpirationDate
MDMStatus
OSVersion
GraphDeviceIsManaged
EasID
SerialNumber
EnrolledByUser
Manufacturer
Model
OSDescription
IsManaged
EasActivationStatus
IMEI
EasLastSyncSuccessUtc
EasStateReason
EasAccessState
EncryptionStatus
SupervisedStatus
PhoneNumberE164Format
InGracePeriodUntil
AndroidPatchLevel
WifiMacAddress
SCCMCoManagementFeatures
MEID
SubscriberCarrierNetwork
StorageTotal
StorageFree
ManagedDeviceName
LastLoggedOnUserUPN
MDMWinsOverGPStartTime
StagedDeviceType
UserApprovedEnrollment
ExtendedProperties
EntitySource
PrimaryUser
CategoryName
UserId
UPN
UserEmail
UserName
RetireAfterDatetime
PartnerDeviceId
HasUnlockToken
CompliantState
ManagedBy
Ownership
DeviceState
DeviceRegistrationState
SupervisedStatusString
EncryptionStatusString
OS
SkuFamily
JoinType
PhoneNumber
JailBroken
EasActivationStatusString

You can choose to filter the Devices report's output based on the following columns:

  • OwnerType
  • DeviceType
  • ManagementAgents
  • CategoryName
  • ManagementState
  • CompliantState
  • JailBroken
  • LastContact
  • CreatedDate
  • EnrollmentType

DetectedAppsAggregate report

The following table contains the possible output when calling the DetectedAppsAggregate report:

Available properties
ApplicationKey
ApplicationName
ApplicationVersion
DeviceCount
BundleSize

You can choose to filter the DetectedAppsAggregate report's output based on the following column:

  • ApplicationName

FeatureUpdatePolicyFailuresAggregate report

The following table contains the possible output when calling the FeatureUpdatePolicyFailuresAggregate report:

Available properties
PolicyId
PolicyName
FeatureUpdateVersion
NumberOfDevicesWithErrors

You cannot filter this report.

DeviceFailuresByFeatureUpdatePolicy report

The following table contains the possible output when calling the DeviceFailuresByFeatureUpdatePolicy report:

Available properties
PolicyId
PolicyName
FeatureUpdateVersion
DeviceId
AADDeviceId
AlertId
EventDateTimeUTC
LastUpdatedAlertStatusDateTimeUTC
AlertType
AlertStatus
AlertClassification
WindowsUpdateVersion
Build
AlertMessage
AlertMessageDescription
AlertMessageData
Win32ErrorCode
RecommendedAction
ExtendedRecommendedAction
StartDateTimeUTC
ResolvedDateTimeUTC
DeviceName
UPN

You can choose to filter the DeviceFailuresByFeatureUpdatePolicy report's output based on the following columns:

  • PolicyId (Required)
  • AlertMessage
  • RecommendedAction
  • WindowsUpdateVersion

FeatureUpdateDeviceState report

The following table contains the possible output when calling the FeatureUpdateDeviceState report:

Available properties
PolicyId
PolicyName
FeatureUpdateVersion
DeviceId
AADDeviceId
PartnerPolicyId
EventDateTimeUTC
LastSuccessfulDeviceUpdateStatus
LastSuccessfulDeviceUpdateSubstatus
LastSuccessfulDeviceUpdateStatusEventDateTimeUTC
CurrentDeviceUpdateStatus
CurrentDeviceUpdateSubstatus
CurrentDeviceUpdateStatusEventDateTimeUTC
LatestAlertMessage
LatestAlertMessageDescription
LatestAlertRecommendedAction
LatestAlertExtendedRecommendedAction
UpdateCategory
WindowsUpdateVersion
LastWUScanTimeUTC
Build
DeviceName
OwnerType
UPN
AggregateState

You can choose to filter the FeatureUpdateDeviceState report's output based on the following columns:

  • PolicyId (Required)
  • AggregateState
  • LatestAlertMessage
  • OwnerType

UnhealthyDefenderAgents and DefenderAgents reports

The UnhealthyDefenderAgents and DefenderAgents reports are two distinct reports that have the same set of properties and filters. The following table contains the possible output when calling the UnhealthyDefenderAgents or DefenderAgents reports:

Available Columns
DeviceId
DeviceName
DeviceState
PendingFullScan
PendingReboot
PendingManualSteps
PendingOfflineScan
CriticalFailure
MalwareProtectionEnabled
RealTimeProtectionEnabled
NetworkInspectionSystemEnabled
SignatureUpdateOverdue
QuickScanOverdue
FullScanOverdue
RebootRequired
FullScanRequired
EngineVersion
SignatureVersion
AntiMalwareVersion
LastQuickScanDateTime
LastFullScanDateTime
LastQuickScanSignatureVersion
LastFullScanSignatureVersion
LastReportedDateTime
UPN
UserEmail
UserName

You can choose to filter the UnhealthyDefenderAgents and DefenderAgents report's output based on the following columns:

  • DeviceState
  • SignatureUpdateOverdue
  • MalwareProtectionEnabled
  • RealTimeProtectionEnabled
  • NetworkInspectionSystemEnabled

ActiveMalware and Malware reports

The ActiveMalware and Malware reports are two distinct reports that have the same set of properties and filters. The following table contains the possible output when calling the ActiveMalware or Malware reports:

Available Columns
DeviceId
DeviceName
MalwareId
MalwareName
AdditionalInformationUrl
Severity
MalwareCategory
ExecutionState
State
InitialDetectionDateTime
LastStateChangeDateTime
DetectionCount
UPN
UserEmail
UserName

You can choose to filter the ActiveMalware and Malware report's output based on the following columns:

  • Severity
  • ExecutionState
  • State

Next steps