Device Query
In brief
The documentation now specifies that Device Query users must be assigned a custom role; the Help Desk Operator role option was removed.
What Intune admins need to know
Review Device Query access and assign an appropriate custom role to administrators who need to use it.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Device query
:::column-end::: :::column span="3":::
To use device query, use an account
with at least one of the following roles:
[Help Desk Operator][Customassigned a [custom role] that includes:
- The permission Managed Devices/Query
- Permissions that provide visibility into and access to managed devices in Intune (for example, Organization/Read, Managed devices/Read) :::column-end:::
@@ -1,8 +1,11 @@ --- title: Device Query description: Learn how to use device query in Microsoft Intune to get on-demand device state, run Kusto Query Language (KQL) queries, and troubleshoot devices.-ms.date: 03/24/2026+ms.date: 09/01/2026 ms.topic: how-to+ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1026+#customer intent: As an IT administrator, I want to query a managed Windows device in real time so that I can investigate security, support, and business issues. --- # Device query@@ -41,9 +44,7 @@ Additional prerequisites for device query: :::column-end::: :::column span="3":::-> To use device query, use an account with at least one of the following roles:-> - [Help Desk Operator]-> - [Custom role] that includes:+> To use device query, use an account assigned a [custom role] that includes: > - The permission **Managed Devices/Query** > - Permissions that provide visibility into and access to managed devices in Intune (for example, Organization/Read, Managed devices/Read) :::column-end:::