Current evidence
Performance and uptime
Review current CPU, memory, disk, network, uptime, and top-process signals before choosing the next diagnostic step.
Intune device diagnostics
Inspect live diagnostics from Microsoft Intune-managed Windows devices, including performance, processes, services, events, hardware, files, and registry state.
Inventory and reports are essential for fleet management. A live support session answers a different question: what is happening on this endpoint while the incident is active?
Current evidence
Current evidence
Review current CPU, memory, disk, network, uptime, and top-process signals before choosing the next diagnostic step.
Current evidence
Search active processes and inspect service state, startup configuration, and the conditions surrounding a failure.
Current evidence
Filter relevant System, Application, Security, and Setup events while the device and incident context remain in view.
Current evidence
Inspect devices, volume capacity, free space, health, and supporting Windows context from the connected endpoint.
Use focused views for the endpoint data relevant to the incident and move between them without exporting a package for every new question.
Browse endpoint paths and retrieve the specific log or artifact required for the investigation.
Inspect keys and values that explain application, policy, Windows, or management-extension behavior.
Review machine certificate health, firewall profiles, enabled rules, and active network context.
Compare installed software and pending update state with the issue reported by the user or service desk.
The same session can continue from observation into a permissioned action and then into a support record.
Use another live tool to confirm the condition before changing the endpoint.
Take the smallest authorized action that addresses the evidence, such as restarting a service or running a diagnostic command.
Re-check the live device after the action instead of waiting for a later inventory or report cycle.
Keep the relevant checks, actions, and result together for the ticket, audit trail, or escalation.
Keep the investigation, controlled action, and support record in one operational flow.
Live support
Confirm connectivity, performance, active processes, services, and the Windows context around the incident.
Live support
Move into events, files, registry, applications, hardware, certificates, or networking as the evidence requires.
Live support
After an approved action, inspect the device again and retain the result in the support-session record.
Practical answers about where IntuneRT fits, how it connects, and how actions stay controlled.
Collect diagnostics creates a diagnostic package for supported scenarios. IntuneRT provides an interactive live session where an administrator can inspect focused endpoint views, ask follow-up questions, and take authorized actions.
No. The device needs the IntuneRT agent, network connectivity, and appropriate tenant configuration, but the administrator can investigate remotely.
Yes. Tool permissions can separate read access from change capabilities so diagnostic roles do not need unrestricted write access.
IntuneRT is designed for managed Windows 10 and Windows 11 devices that meet the agent and tenant deployment requirements.
Continue from the support outcome you need into the live tools that help deliver it.
Connect live diagnostics, focused actions, and session evidence in one support workflow.
Use a focused command when live diagnostic evidence requires a deeper or custom check.
Review the complete set of focused IntuneRT tools for managed Windows endpoints.
Try IntuneRT with up to 5 devices and move from current endpoint evidence to accountable action.