Available tools
Find devices
Find devices
@Find DevicesInput fields:- Serial number
- Device name
- Model (e.g., “Surface Pro”, “iPhone 15”, “ThinkPad X1”)
- Operating system (e.g., “Windows”, “iOS”, “Android”, “macOS”)
- Device name, operating system, OS version
- Model, manufacturer, serial number
- Compliance state, last sync time
- Device ID, enrollment date, management state
- Primary user (UPN)
- Look up requester devices when troubleshooting hardware or software issues
- Verify device compliance before approving access requests
- Identify device details for IT support workflows
- Check when a device last synced with Intune
When a user reports a device issue, use @Find Devices to look up their managed devices. If the device is non-compliant, inform the user of the compliance issue before troubleshooting.
Get device apps
Get device apps
@Get Device AppsInput fields:- Intune managed device ID (from Find Devices results)
- App name filter (optional, substring match)
- Platform filter (optional, e.g., “windows”, “ios”, “macOS”)
- Publisher filter (optional, substring match)
- Application name, version, publisher
- Platform
- App ID
- Verify whether a specific application is installed on a user’s device
- Audit installed software for compliance or licensing checks
- Troubleshoot application issues by checking installed versions
- Identify outdated software that needs updating
When a user reports a software issue, use @Find Devices and @Get Device Apps to check which applications and versions are on their device. Inform the user if the application is missing or outdated.
Autopilot reset
Autopilot reset
@Autopilot ResetInput fields:- Device (resolved from ticket context)
- Reset a user’s device when troubleshooting reveals a system-level issue
- Reprovision devices as part of automated IT support workflows
- Prepare a device for a new user assignment
If the user needs their Windows device fully reset, use @Find Devices to locate the device, then use @Autopilot Reset to wipe and reprovision it. Confirm with the user that the reset has been queued.
Retire device
Retire device
@Retire DeviceInput fields:- Device (resolved from ticket context)
- Remove corporate data from a BYOD device during offboarding
- Retire devices that should no longer be managed
- Automate device retirement in offboarding workflows
When processing an offboarding request for a BYOD user, use @Find Devices to locate their personal device, then use @Retire Device to remove corporate data. Notify the user that company data has been removed from their device.
Sync device
Sync device
@Sync DeviceInput fields:- Device (resolved from ticket context)
- Push urgent policy updates when a user reports missing configurations
- Verify a device picks up new compliance requirements
- Troubleshoot devices that appear out of sync
When a user reports they are missing an expected policy or configuration, use @Find Devices to locate their device, then use @Sync Device to force a check-in. Let the user know their device is syncing and to check again in a few minutes.
Rotate BitLocker key
Rotate BitLocker key
@Rotate BitLocker KeyInput fields:- Device (resolved from ticket context)
- Rotate recovery keys after they have been shared during support
- Implement security compliance key rotation
- Respond to incidents by rotating encryption keys
After helping a user with a BitLocker recovery, use @Find Devices to locate their device, then use @Rotate BitLocker Key to generate a new recovery key. Inform the user that their recovery key has been rotated for security.
Wipe device
Wipe device
@Wipe DeviceInput fields:- Device (resolved from ticket context)
- macOS unlock code (only for macOS devices)
- Wipe lost or stolen devices to protect corporate data
- Prepare devices for decommissioning
- Respond to security incidents requiring immediate data removal
If a user reports a lost or stolen device, use @Find Devices to locate it, then use @Wipe Device to remotely erase all data. If the device is macOS, provide the unlock code to the user's manager via a private note.
Assign script
Assign script
@Assign ScriptInput fields:- Script ID
- Entra group
- Organization
- Deploy remediation scripts to affected teams
- Assign configuration scripts during onboarding
- Automate script deployment based on ticket context
When a user needs a specific configuration applied to their device, use @Assign Script to deploy the relevant remediation script to their group. Confirm to the user that the script has been assigned and will run on their next device check-in.
Setup
Install Intune integration
Configure agent
Create rules
Test the tool
Best practices
- Device results are automatically scoped to the ticket requester’s email, so no additional user filtering is needed
- Combine device lookup with compliance checks in access request workflows
- Use serial number for precise device identification when the requester has multiple devices
- Chain Find Devices with Get Device Apps for complete device audits: look up the device first, then check its installed applications
- Use the app name, platform, and publisher filters in Get Device Apps to narrow results when a device has many installed applications