Microsoft Intune
Windows

Collect Device Properties With Intune Properties Catalog

In brief

Updated Microsoft Intune documentation in intune/device-configuration/collect-device-properties.md.

What Intune admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Open the full-page diff for complete context.

Use the Intune properties catalog to getcollect device hardware properties from Windows devices

In Microsoft Intune, you can use the properties catalog to collect device properties—including hardware details, configuration data, and view hardware properties application signals—from your managed Windows devices. When you create the policy, you can select specific properties to collect.

For example, you can:

  • Discover local AI agents, like OpenClaw, running on your Windows devices.
  • Collect selected Windows registry key values from managed Windows devices, such as configuration settings, application state, or security posture signals.
  • Get the BIOS version and TPM status to identify devices that might need firmware updates or aren't compliant with security policies.
  • Identify devices that lack encryption, which might violate security policies.
  • Identify devices that need to be replaced based on hardware properties, like disk size or memory.
  • Collect battery health information to help monitor device performance and lifespan.
  • Retrieve network adapter configurations to troubleshoot connectivity issues.

UseThis visibility helps you make informed decisions about device compliance, lifecycle management, and troubleshooting.

In this information to get deeper visibility into your device inventory, including detailed hardware and system information.

This article showsarticle, you'll learn how to configurecreate a properties catalog policy, view the data collected by the policy,data, and listsexplore the available hardware properties. After you createcreating a profile, you can assign or deploy that profileit to your Windows devices.

Prerequisites

This feature applies to:

  • Windows

Prerequisites

:::row::: :::column span="1"::: [!INCLUDE platform:::row::: :::column span="1"::: [!INCLUDE platform]

:::column-end::: :::column span="3":::

This feature supports the following platforms:Windows devices only.

On Android and Apple devices, device properties are collected automatically. :::column-end::: :::row-end:::

:::row::: :::column span="1"::: [!INCLUDE device-configuration]

:::column-end::: :::column span="3":::

This feature supports devices that are:

  • WindowsManaged by Intune
  • Devices must be corporate owned, Intune Co-managed (includes co-managed), (Intune + Configuration Manager)
  • Microsoft Entra Hybrid joined, and joined
  • Microsoft Entra joined.hybrid joined :::column-end::: :::row-end:::

:::column-end::: :::column span="3":::

Role requirements vary based on the tasks being performed.


To configure this policy and start collecting inventory data from devices,the properties catalog policy, use an account with at least one of the following Intune roles:


To view the collected data, use an account with the permission and the Organization > Read permission.

  • For a user to view collected data about devices, they must have the Managed Devices > Devices/Read permission. This permission is included in many built-in roles. For a list, see Built-in role permissions for Microsoft Intune. :::column-end::: :::row-end:::
  • Create the policy

    Use the following steps to create a properties catalog profile and assign it to your Windows devices.

    1. Sign in to the Microsoft Intune admin center.

    2. Select Devices > Manage devices > Configuration > Create > New Policy.

    3. Enter the following properties and select Create:

      • Platform: Select Windows 10 and later.
      • Profile type: Select Properties catalog.
    4. In Basics, enter the following properties and select Next:

      • Name: Enter a descriptive name for the new profile.
      • Description: Enter a description for the profile. This setting is optional, but recommended.
    5. Select Add properties and select the properties you want to collect. You can select multiple properties from multiple categories.

      Some required properties are automatically added. For a list, see Required properties (in this article).

      Select Next.

    6. Optional. In Scope (Tags), select any scope tags you want to assign to the profile. To learn more about scope tags, see Use scope tags for distributed IT.

      Select Next.

    7. In Assignments, select the groups that receive this profile. For more information on assigning profiles, see Assign user and device profiles.

      Select Next.

    8. In Review + create, review your settings, and select Create.

      When you select Create, the profile is assigned to the groups you specified. The profile is also created and shown in the list.

    The next time each device checks in with the Intune service, the policy applies. It can take up to 24 hours for the initial collection of inventory data.

    Available and required properties

    You can collect the following properties. To learn more about the different properties, see Intune Data Platform Schema.

    When you create the policy, select any of the following property categories to collect. The required properties are automatically collected when you collect any property in that category.

    Category Required properties
    Application Properties App Name
    App Version
    Architectures
    Install Scope
    Install Scope Platform User ID
    Install Scope User ID
    Publisher
    Battery Instance Name
    Bios Info Bios Name
    Software Element ID
    Software Element State
    Target Operating System
    CPU Processor ID
    Disk Drive Drive ID
    Encryptable Volume Volume ID
    Local AI Agent Agent Name
    Install Location
    Install Scope

    Microsoft recommends collecting Host process, as OpenClaw can run in different process names, like node.exe, wsl.exe, etc.
    Logical Drive Drive Identifier
    Memory Info
    Network Adapter Identifier
    OS Version
    Sim Info Windows eSIM ID
    RegistryRegistry keys
    System Enclosure Serial Number
    System Info
    Time
    TPM
    Video Controller Identifier
    Windows QFE Hot Fix ID

    View collected dataCreate the collection policy

    Use the following steps to view the collected device inventory information:create a properties catalog profile and assign it to your Windows devices.

    1. Sign in to

      In the Microsoft Intune admin center.

    2. Go to[Microsoft Intune admin center], select Devices > By platformWindows.
    3. Under Manage devices, select Configuration > Create > New Policy.

    4. Select the following properties and select Create:

      • Platform: Select Windows Devices10 and later.
      • Profile type: Select Properties catalog.
    5. In Basics, enter the following properties and select Next:

      • Name: Enter a descriptive name for the new profile.
      • Description: Enter a description for the profile. This setting is optional, but recommended.
    6. Select Add properties and select the properties you want to collect. You can select multiple properties from multiple categories.

      Some required properties are automatically added. For a device.list, see Required properties.

      Select Next.

    7. Optional. In MonitorScope (Tags), select any scope tags you want to assign to the profile. To learn more about scope tags, see Use scope tags for distributed IT.

      Select Device InventoryNext.

    8. In Assignments, select the groups that receive this profile. For more information on assigning profiles, see Assign policies in Microsoft Intune.

      Select a category to view the hardware information.Next.

    9. In Review + create, review your settings, and select Create.

    What

    When you needselect Create, the profile is assigned to know

    • Local AI Agent helpsthe groups you discover OpenClaw running on your Windows devices. After you deployspecified. The profile is also created and shown in the properties cataloglist. The next time each device checks in with the Intune service, the policy and start collecting data, the next steps are:applies.

      • Use Device Query

        View collected data

        Use the following steps to view the collected device inventory information:

        1. In the [Microsoft Intune admin center], select Devices > Windows.
        2. From the devices list, select a device.
        3. Under Tools, select Device Inventory.
        4. Select a category to view the collected information.

        Feature details and usage

        :::row::: :::column span="1"::: Local AI agent

        :::column-end::: :::column span="3":::

        Helps you discover OpenClaw running on your Windows devices. After you deploy the properties catalog policy and start collecting data, the next steps are:

        :::row::: :::column span="1"::: Registry key inventory

        :::column-end::: :::column span="3":::

        Lets you collect selected Windows registry data through the properties catalog for configuration visibility and troubleshooting. Here are some important details about this feature:

        • Supported collection methods include a single value, all values directly under a key (non-recursive), and the same value across immediate subkeys.
        • Registry key inventory isn't intended to collect sensitive or confidential values and includes detection logic to help prevent potentially sensitive values from being ingested. If a value is flagged as potentially sensitive, it isn't collected.
        • To view collected registry data, use Device Inventory.
        • Initial release limitations include HKLM-only collection and enforced value (6KB) and per-device (100 registry keys) collection limits. :::column-end::: :::row-end:::

        Stop collecting properties

        You can stop (delete) the collection of properties only at the category level. To stop collecting properties, go to the properties catalog profile, and remove the collection for every property in the category.

        If you delete a properties catalog policy, you can see the last-collected data in Device Inventory for up to 28 days.

      • If you use co-management with tenant attach, you see the Resource Explorer and Device Inventory nodes.

        For Intune collected data, you see a Device Inventory tab. For Configuration Manager collected data, you see a Resource Explorer tab. Use the source that best fits your use case. In the future, use the Intune-based Device Inventory

        Troubleshooting

        To troubleshoot issues with the properties catalog, review the client logs at C:\Program Files\Microsoft Device Inventory Agent\Logs. You can also collect the logs by using the Device Action: Collect Diagnostics.

      • The client logs are at C:\Program Files\Microsoft Device Inventory Agent\Logs. You can also collect the logs by using the Remote device action: collect diagnostics. Use these logs to help troubleshoot.

      Related content

      \ No newline at end of file [Custom role]: ../fundamentals/role-based-access-control/create-custom-role.md \ No newline at end of file

    Daily Intune.Admin.News

    Get daily email updates

    Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

    Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.