Skip to main content

Intune device diagnostics

See live Intune device diagnostics before you act

Inspect live diagnostics from Microsoft Intune-managed Windows devices, including performance, processes, services, events, hardware, files, and registry state.

Live device performance
Processes and services
Events and endpoint data
Connected support context

See the device state that exists now.

Inventory and reports are essential for fleet management. A live support session answers a different question: what is happening on this endpoint while the incident is active?

Current evidence

01

Current evidence

Performance and uptime

Review current CPU, memory, disk, network, uptime, and top-process signals before choosing the next diagnostic step.

02

Current evidence

Processes and services

Search active processes and inspect service state, startup configuration, and the conditions surrounding a failure.

03

Current evidence

Windows event logs

Filter relevant System, Application, Security, and Setup events while the device and incident context remain in view.

04

Current evidence

Hardware and storage

Inspect devices, volume capacity, free space, health, and supporting Windows context from the connected endpoint.

Investigate beyond a single diagnostics bundle.

Use focused views for the endpoint data relevant to the incident and move between them without exporting a package for every new question.

Endpoint detail

  1. Files

    Browse endpoint paths and retrieve the specific log or artifact required for the investigation.

Endpoint detail

  1. Registry

    Inspect keys and values that explain application, policy, Windows, or management-extension behavior.

Endpoint detail

  1. Certificates and firewall

    Review machine certificate health, firewall profiles, enabled rules, and active network context.

Endpoint detail

  1. Applications and updates

    Compare installed software and pending update state with the issue reported by the user or service desk.

Turn diagnostic evidence into a support outcome.

The same session can continue from observation into a permissioned action and then into a support record.

Faster decisions

  1. Validate the suspected cause

    Use another live tool to confirm the condition before changing the endpoint.

Faster decisions

  1. Apply a targeted response

    Take the smallest authorized action that addresses the evidence, such as restarting a service or running a diagnostic command.

Faster decisions

  1. Confirm the new state

    Re-check the live device after the action instead of waiting for a later inventory or report cycle.

Faster decisions

  1. Preserve the evidence

    Keep the relevant checks, actions, and result together for the ticket, audit trail, or escalation.

From live evidence to a documented outcome.

Keep the investigation, controlled action, and support record in one operational flow.

01

Live support

Establish the live baseline

Confirm connectivity, performance, active processes, services, and the Windows context around the incident.

02

Live support

Narrow the investigation

Move into events, files, registry, applications, hardware, certificates, or networking as the evidence requires.

03

Live support

Verify the outcome

After an approved action, inspect the device again and retain the result in the support-session record.

Questions from Intune administrators.

Practical answers about where IntuneRT fits, how it connects, and how actions stay controlled.

FAQ

  1. How is this different from Intune Collect diagnostics?

    Collect diagnostics creates a diagnostic package for supported scenarios. IntuneRT provides an interactive live session where an administrator can inspect focused endpoint views, ask follow-up questions, and take authorized actions.

FAQ

  1. Do administrators need physical access to the device?

    No. The device needs the IntuneRT agent, network connectivity, and appropriate tenant configuration, but the administrator can investigate remotely.

FAQ

  1. Can an administrator inspect only read-only data?

    Yes. Tool permissions can separate read access from change capabilities so diagnostic roles do not need unrestricted write access.

FAQ

  1. Which Windows versions are supported?

    IntuneRT is designed for managed Windows 10 and Windows 11 devices that meet the agent and tenant deployment requirements.

Continue from the support outcome you need into the live tools that help deliver it.

Related capability

  1. Intune remote troubleshooting

    Connect live diagnostics, focused actions, and session evidence in one support workflow.

Related capability

  1. Remote PowerShell for Intune devices

    Use a focused command when live diagnostic evidence requires a deeper or custom check.

Related capability

  1. Explore the live toolkit

    Review the complete set of focused IntuneRT tools for managed Windows endpoints.

Start a live Intune troubleshooting session.

Try IntuneRT with up to 5 devices and move from current endpoint evidence to accountable action.

  • 5-device free tier
  • No credit card
  • Microsoft sign-in