Collect Device Properties With Intune Properties Catalog
In brief
Updated Microsoft Intune documentation in intune/device-configuration/collect-device-properties.md.
What Intune admins need to know
Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Open the full-page diff for complete context.
Use the Intune properties catalog to getcollect device hardware properties from Windows devices
In Microsoft Intune, you can use the properties catalog to collect device properties—including hardware details, configuration data, and view hardware properties application signals—from your managed Windows devices. When you create the policy, you can select specific properties to collect.
For example, you can:
- Discover local AI agents, like OpenClaw, running on your Windows devices.
- Collect selected Windows registry key values from managed Windows devices, such as configuration settings, application state, or security posture signals.
- Get the BIOS version and TPM status to identify devices that might need firmware updates or aren't compliant with security policies.
- Identify devices that lack encryption, which might violate security policies.
- Identify devices that need to be replaced based on hardware properties, like disk size or memory.
- Collect battery health information to help monitor device performance and lifespan.
- Retrieve network adapter configurations to troubleshoot connectivity issues.
UseThis visibility helps you make informed decisions about device compliance, lifecycle management, and troubleshooting.
In this information to get deeper visibility into your device inventory, including detailed hardware and system information.
This article showsarticle, you'll learn how to configurecreate a properties catalog policy, view the data collected by the policy,data, and listsexplore the available hardware properties. After you createcreating a profile, you can assign or deploy that profileit to your Windows devices.
Prerequisites
This feature applies to:
Windows
Prerequisites
:::row::: :::column span="1"::: [!INCLUDE platform
:::column-end::: :::column span="3":::
This feature supports
the following platforms:Windows devices only.On Android and Apple devices, device properties are collected automatically. :::column-end::: :::row-end:::
:::row::: :::column span="1"::: [!INCLUDE device-configuration]
:::column-end::: :::column span="3":::
This feature supports devices that are:
WindowsManaged by IntuneDevices must be corporate owned, IntuneCo-managed(includes co-managed),(Intune + Configuration Manager)- Microsoft Entra
Hybrid joined, andjoined- Microsoft Entra
joined.hybrid joined :::column-end::: :::row-end:::
:::column-end::: :::column span="3":::
Role requirements vary based on the tasks being performed.
To configure
this policy and start collecting inventory data from devices,the properties catalog policy, use an account with at least one of the following Intune roles:
[!INCLUDE minimum-rbac-role-policy-profile-manager]Policy and Profile Manager- A
custom role[custom role] that includes the permissions:
- Organization/Read and Managed Devices/Read — Required for device visibility.
- Device
Configurationsconfigurations/Create, Read, Assign>Create— Required to create and assign the data collection policy.To view the collected data, use an account with the permission
and theOrganization>Readpermission.For a user to view collected data about devices, they must have theManagedDevices>Devices/Readpermission. This permission is included in many built-in roles. For a list, see Built-in role permissions for Microsoft Intune. :::column-end::: :::row-end:::
Create the policy
Use the following steps to create a properties catalog profile and assign it to your Windows devices.
Sign in to the Microsoft Intune admin center.SelectDevices>Manage devices>Configuration>Create>New Policy.Enter the following properties and selectCreate:Platform: SelectWindows 10 and later.Profile type: SelectProperties catalog.
InBasics, enter the following properties and selectNext:Name: Enter a descriptive name for the new profile.Description: Enter a description for the profile. This setting is optional, but recommended.
SelectAdd propertiesand select the properties you want to collect. You can select multiple properties from multiple categories.Some required properties are automatically added. For a list, see Required properties (in this article).SelectNext.Optional. InScope (Tags), select any scope tags you want to assign to the profile. To learn more about scope tags, see Use scope tags for distributed IT.SelectNext.InAssignments, select the groups that receive this profile. For more information on assigning profiles, see Assign user and device profiles.SelectNext.InReview + create, review your settings, and selectCreate.When you selectCreate, the profile is assigned to the groups you specified. The profile is also created and shown in the list.
The next time each device checks in with the Intune service, the policy applies. It can take up to 24 hours for the initial collection of inventory data.
Available and required properties
You can collect the following properties. To learn more about the different properties, see Intune Data Platform Schema.
When you create the policy, select any of the following property categories to collect. The required properties are automatically collected when you collect any property in that category.
| Category | Required properties |
|---|---|
| Application Properties | App Name App Version Architectures Install Scope Install Scope Platform User ID Install Scope User ID Publisher |
| Battery | Instance Name |
| Bios Info | Bios Name Software Element ID Software Element State Target Operating System |
| CPU | Processor ID |
| Disk Drive | Drive ID |
| Encryptable Volume | Volume ID |
| Local AI Agent | Agent Name Install Location Install Scope Microsoft recommends collecting Host process, as OpenClaw can run in different process names, like node.exe, wsl.exe, etc. |
| Logical Drive | Drive Identifier |
| Memory Info | — |
| Network Adapter | Identifier |
| OS Version | — |
| Sim Info | Windows eSIM ID |
| Registry | Registry keys |
| System Enclosure | Serial Number |
| System Info | — |
| Time | — |
| TPM | — |
| Video Controller | Identifier |
| Windows QFE | Hot Fix ID |
View collected dataCreate the collection policy
Use the following steps to view the collected device inventory information:create a properties catalog profile and assign it to your Windows devices.
Sign in toIn the
Microsoft Intune admin center.Go to[Microsoft Intune admin center], select Devices >By platformWindows.Under Manage devices, select Configuration > Create > New Policy.
Select the following properties and select Create:
- Platform: Select Windows
Devices10 and later. - Profile type: Select Properties catalog.
- Platform: Select Windows
In Basics, enter the following properties and select Next:
- Name: Enter a descriptive name for the new profile.
- Description: Enter a description for the profile. This setting is optional, but recommended.
Select Add properties and select the properties you want to collect. You can select multiple properties from multiple categories.
Some required properties are automatically added. For a
device.list, see Required properties.Select Next.
Optional. In
MonitorScope (Tags), select any scope tags you want to assign to the profile. To learn more about scope tags, see Use scope tags for distributed IT.Select
Device InventoryNext.In Assignments, select the groups that receive this profile. For more information on assigning profiles, see Assign policies in Microsoft Intune.
Select
a category to view the hardware information.Next.In Review + create, review your settings, and select Create.
What
When you needselect Create, the profile is assigned to know
Local AI Agenthelpsthe groups youdiscover OpenClaw running on your Windows devices. After you deployspecified. The profile is also created and shown in theproperties cataloglist. The next time each device checks in with the Intune service, the policyand start collecting data, the next steps are:applies.Use Device QueryView collected data
Use the following steps to view the collected device inventory information:
- In the [Microsoft Intune admin center], select Devices > Windows.
- From the devices list, select a device.
- Under Tools, select Device Inventory.
- Select a category to view the collected information.
Feature details and usage
:::row::: :::column span="1"::: Local AI agent
:::column-end::: :::column span="3":::
to view devices with a Local AI Agent.Helps you discover OpenClaw running on your Windows devices. After you deploy the properties catalog policy and start collecting data, the next steps are:
- Use Device Query
- Use the Local AI Agent Baseline - OpenClaw to block users from using OpenClaw. :::column-end::: :::row-end:::
:::row::: :::column span="1"::: Registry key inventory
:::column-end::: :::column span="3":::
Lets you collect selected Windows registry data through the properties catalog for configuration visibility and troubleshooting. Here are some important details about this feature:
- Supported collection methods include a single value, all values directly under a key (non-recursive), and the same value across immediate subkeys.
- Registry key inventory isn't intended to collect sensitive or confidential values and includes detection logic to help prevent potentially sensitive values from being ingested. If a value is flagged as potentially sensitive, it isn't collected.
- To view collected registry data, use Device Inventory.
- Initial release limitations include HKLM-only collection and enforced value (6KB) and per-device (100 registry keys) collection limits. :::column-end::: :::row-end:::
Stop collecting properties
You can stop (delete) the collection of properties only at the category level. To stop collecting properties, go to the properties catalog profile, and remove the collection for every property in the category.
If you delete a properties catalog policy, you can see the last-collected data in Device Inventory for up to 28 days.If you use co-management with tenant attach, you see theResource ExplorerandDevice Inventorynodes.For Intune collected data, you see aDevice Inventorytab. For Configuration Manager collected data, you see aResource Explorertab. Use the source that best fits your use case. In the future, use the Intune-basedDevice InventoryTroubleshooting
To troubleshoot issues with the properties catalog, review the client logs at
.C:\Program Files\Microsoft Device Inventory Agent\Logs. You can also collect the logs by using the Device Action: Collect DiagnosticsThe client logs are atC:\Program Files\Microsoft Device Inventory Agent\Logs. You can also collect the logs by using the Remote device action: collect diagnostics. Use these logs to help troubleshoot.
Related content
\ No newline at end of file [Custom role]: ../fundamentals/role-based-access-control/create-custom-role.md \ No newline at end of file
@@ -1,18 +1,20 @@ ----title: "Collect Device Hardware Info With the Properties Catalog"-description: "Use the properties catalog in Microsoft Intune to collect device hardware info like BIOS version, TPM status, and disk details on managed Windows devices. Get deeper visibility into your device inventory and troubleshoot issues."-ms.date: 06/03/2026+title: Collect Device Properties With Intune Properties Catalog+description: Use Microsoft Intune properties catalog to collect device properties—including hardware, registry values, and security signals—from Windows devices.+ms.date: 07/01/2026 ms.topic: how-to+ai-usage: ai-assisted ms.reviewer: abbystarr, madisoncooks --- -# Use the Intune properties catalog to get device hardware properties+# Use Intune properties catalog to collect device properties from Windows devices -In Microsoft Intune, you can use the **properties catalog** to collect and view hardware properties from your managed Windows devices. When you create the policy, you can select specific properties to collect.+In Microsoft Intune, use the **properties catalog** to collect device properties—including hardware details, configuration data, and application signals—from managed Windows devices. For example, you can: - Discover local AI agents, like OpenClaw, running on your Windows devices.+- Collect selected Windows registry key values from managed Windows devices, such as configuration settings, application state, or security posture signals. - Get the BIOS version and TPM status to identify devices that might need firmware updates or aren't compliant with security policies. - Identify devices that lack encryption, which might violate security policies. - Identify devices that need to be replaced based on hardware properties, like disk size or memory.@@ -20,29 +22,36 @@ For example, you can: - Collect battery health information to help monitor device performance and lifespan. - Retrieve network adapter configurations to troubleshoot connectivity issues. -Use this information to get deeper visibility into your device inventory, including detailed hardware and system information.+This visibility helps you make informed decisions about device compliance, lifecycle management, and troubleshooting. -This article shows you how to configure a properties catalog policy, view the data collected by the policy, and lists the available properties. After you create a profile, assign or deploy that profile to your Windows devices.+In this article, you'll learn how to create a properties catalog policy, view the collected data, and explore the available hardware properties. After creating a profile, you can assign it to your Windows devices. -This feature applies to:+## Prerequisites -- Windows+:::row:::+:::column span="1":::+[!INCLUDE [platform](../includes/requirements/platform.md)] -> [!NOTE]+:::column-end:::+:::column span="3":::+> This feature supports Windows devices only.+> > On Android and Apple devices, device properties are collected automatically.--## Prerequisites+:::column-end:::+:::row-end::: :::row::: :::column span="1":::-[!INCLUDE [platform](../includes/requirements/platform.md)]+[!INCLUDE [device-configuration](../includes/requirements/device-configuration.md)] :::column-end::: :::column span="3":::-> This feature supports the following platforms:+> This feature supports devices that are: >-> - Windows-> - Devices must be corporate owned, Intune managed (includes co-managed), Microsoft Entra Hybrid joined, and Microsoft Entra joined.+> - Managed by Intune+> - Co-managed (Intune + Configuration Manager)+> - Microsoft Entra joined+> - Microsoft Entra hybrid joined :::column-end::: :::row-end::: @@ -52,108 +61,148 @@ This feature applies to: :::column-end::: :::column span="3":::-> To configure this policy and start collecting inventory data from devices, use an account with at least one of the following roles:+> Role requirements vary based on the tasks being performed.+>+> ---+>+> To configure the properties catalog policy, use an account with at least one of the following Intune roles: >-> - [!INCLUDE [minimum-rbac-role-policy-profile-manager](../includes/minimum-rbac-role-policy-profile-manager.md)]-> - A [custom role](./templates/configure-custom-settings.md) that includes the **Device Configurations** > **Create** permission and the **Organization** > **Read** permission.-> - For a user to view collected data about devices, they must have the **Managed Devices** > **Read** permission. This permission is included in many built-in roles. For a list, see [Built-in role permissions for Microsoft Intune](../fundamentals/role-based-access-control/ref-built-in-roles.md).+> - [Policy and Profile Manager](../fundamentals/role-based-access-control/ref-built-in-roles.md#policy-and-profile-manager)+> - A [custom role] that includes the permissions:+> - **Organization/Read** and **Managed Devices/Read** — Required for device visibility.+> - **Device configurations/Create, Read, Assign** — Required to create and assign the data collection policy.+>+> ---+>+> To view the collected data, use an account with the permission **Managed Devices/Read**. :::column-end::: :::row-end::: -## Create the policy+## Available and required properties -Use the following steps to create a properties catalog profile and assign it to your Windows devices.+You can collect the following properties. To learn more about the different properties, see [Intune Data Platform Schema](../advanced-analytics/ref-data-platform-schema.md). -1. Sign in to the [Microsoft Intune admin center].+When you create the policy, select any of the following property categories to collect. The **required** properties are automatically collected when you collect any property in that category. -2. Select **Devices** > **Manage devices** > **Configuration** > **Create** > **New Policy**.+| Category | Required properties |+|--|--|+| Application Properties | App Name<br/>App Version<br/>Architectures<br/>Install Scope<br/>Install Scope Platform User ID<br/>Install Scope User ID<br/>Publisher |+| Battery | Instance Name |+| Bios Info | Bios Name<br/>Software Element ID<br/>Software Element State<br/>Target Operating System |+| CPU | Processor ID |+| Disk Drive | Drive ID |+| Encryptable Volume | Volume ID |+| Local AI Agent | Agent Name<br/>Install Location<br/>Install Scope <br/><br/>Microsoft recommends collecting **Host process**, as OpenClaw can run in different process names, like `node.exe`, `wsl.exe`, etc. |+| Logical Drive | Drive Identifier |+| Memory Info | — |+| Network Adapter | Identifier |+| OS Version | — |+| Sim Info | Windows eSIM ID |+| Registry | Registry keys |+| System Enclosure | Serial Number |+| System Info | — |+| Time | — |+| TPM | — |+| Video Controller | Identifier |+| Windows QFE | Hot Fix ID | -3. Enter the following properties and select **Create**:+## Create the collection policy++Use the following steps to create a properties catalog profile and assign it to your Windows devices.++1. In the [Microsoft Intune admin center], select **Devices** > **Windows**.+1. Under **Manage devices**, select **Configuration** > **Create** > **New Policy**.+1. Select the following properties and select **Create**: - **Platform**: Select **Windows 10 and later**. - **Profile type**: Select **Properties catalog**. -4. In **Basics**, enter the following properties and select **Next**:+1. In **Basics**, enter the following properties and select **Next**: - **Name**: Enter a descriptive name for the new profile. - **Description**: Enter a description for the profile. This setting is optional, but recommended. -5. Select **Add properties** and select the properties you want to collect. You can select multiple properties from multiple categories.+1. Select **Add properties** and select the properties you want to collect. You can select multiple properties from multiple categories. - Some required properties are automatically added. For a list, see [Required properties](#available-and-required-properties) (in this article).+ Some required properties are automatically added. For a list, see [Required properties](#available-and-required-properties). Select **Next**. -6. Optional. In **Scope (Tags)**, select any scope tags you want to assign to the profile. To learn more about scope tags, see [Use scope tags for distributed IT](../fundamentals/role-based-access-control/scope-tags.md).+1. Optional. In **Scope (Tags)**, select any scope tags you want to assign to the profile. To learn more about scope tags, see [Use scope tags for distributed IT](../fundamentals/role-based-access-control/scope-tags.md). Select **Next**. -7. In **Assignments**, select the groups that receive this profile. For more information on assigning profiles, see [Assign user and device profiles](./assign-device-profile.md).+1. In **Assignments**, select the groups that receive this profile. For more information on assigning profiles, see [Assign policies in Microsoft Intune](./assign-device-profile.md). Select **Next**. -8. In **Review + create**, review your settings, and select **Create**.+1. In **Review + create**, review your settings, and select **Create**. - When you select **Create**, the profile is assigned to the groups you specified. The profile is also created and shown in the list.+When you select **Create**, the profile is assigned to the groups you specified. The profile is also created and shown in the list. The next time each device checks in with the Intune service, the policy applies. -The next time each device checks in with the Intune service, the policy applies. It can take up to 24 hours for the initial collection of inventory data.+> [!NOTE]+> It can take up to 24 hours for the initial collection of inventory data. -## Available and required properties+## View collected data -You can collect the following properties. To learn more about the different properties, see [Intune Data Platform Schema](../advanced-analytics/ref-data-platform-schema.md).+Use the following steps to view the collected device inventory information: -When you create the policy, select any of the following property categories to collect. The **required** properties are automatically collected when you collect any property in that category.+1. In the [Microsoft Intune admin center], select **Devices** > **Windows**.+1. From the devices list, select a device.+1. Under **Tools**, select **Device Inventory**.+1. Select a category to view the collected information. -| Category | Required properties |-| --- | --- |-| Application Properties | App Name<br/>App Version<br/>Architectures<br/>Install Scope<br/>Install Scope Platform User ID<br/>Install Scope User ID<br/>Publisher |-| Battery | Instance Name |-| Bios Info | Bios Name<br/>Software Element ID<br/>Software Element State<br/>Target Operating System |-| CPU | Processor ID |-| Disk Drive | Drive ID |-| Encryptable Volume | Volume ID |-| Local AI Agent | Agent Name<br/>Install Location<br/>Install Scope <br/><br/>Microsoft recommends collecting **Host process**, as OpenClaw can run in different process names, like `node.exe`, `wsl.exe`, etc. |-| Logical Drive | Drive Identifier |-| Memory Info | |-| Network Adapter | Identifier |-| OS Version | |-| Sim Info | Windows eSIM ID |-| System Enclosure | Serial Number |-| System Info | |-| Time | |-| TPM | |-| Video Controller | Identifier |-| Windows QFE | Hot Fix ID |+## Feature details and usage -## View collected data+:::row:::+:::column span="1":::+**Local AI agent** -Use the following steps to view the collected device inventory information:+:::column-end:::+:::column span="3":::+> Helps you discover OpenClaw running on your Windows devices. After you deploy the properties catalog policy and start collecting data, the next steps are:+>+> - Use [Device Query](../advanced-analytics/device-query-multiple-devices.md) to view devices with a Local AI Agent.+> - Use the [Local AI Agent Baseline - OpenClaw](../device-security/security-baselines/ref-openclaw-settings.md) to block users from using OpenClaw.+:::column-end:::+:::row-end::: -1. Sign in to the [Microsoft Intune admin center].-2. Go to **Devices** > **By platform** > **Windows Devices** and select a device.-3. In **Monitor**, select **Device Inventory**. Select a category to view the hardware information.+:::row:::+:::column span="1":::+**Registry key inventory** -## What you need to know+:::column-end:::+:::column span="3":::+>Lets you collect selected Windows registry data through the properties catalog for configuration visibility and troubleshooting. Here are some important details about this feature:+> - Supported collection methods include a single value, all values directly under a key (non-recursive), and the same value across immediate subkeys.+> - Registry key inventory isn't intended to collect sensitive or confidential values and includes detection logic to help prevent potentially sensitive values from being ingested. If a value is flagged as potentially sensitive, it isn't collected.+> - To view collected registry data, use Device Inventory.+> - Initial release limitations include HKLM-only collection and enforced value (6KB) and per-device (100 registry keys) collection limits.+:::column-end:::+:::row-end::: -- **Local AI Agent** helps you discover OpenClaw running on your Windows devices. After you deploy the properties catalog policy and start collecting data, the next steps are:+## Stop collecting properties - - Use [Device Query](../advanced-analytics/device-query-multiple-devices.md) to view devices with a Local AI Agent.- - Use the [Local AI Agent Baseline - OpenClaw](../device-security/security-baselines/ref-openclaw-settings.md) to block users from using OpenClaw.+You can stop (delete) the collection of properties only at the category level. To stop collecting properties, go to the **properties catalog** profile, and remove the collection for every property in the category. -- You can stop (delete) the collection of properties only at the category level. To stop collecting properties, go to the **properties catalog** profile, and remove the collection for every property in the category.+> [!NOTE]+> If you delete a properties catalog policy, you can see the last-collected data in Device Inventory for up to 28 days.++## Troubleshooting - If you delete a properties catalog policy, you can see the last-collected data in Device Inventory for up to 28 days.+To troubleshoot issues with the properties catalog, review the client logs at `C:\Program Files\Microsoft Device Inventory Agent\Logs`. You can also collect the logs by using the [Device Action: Collect Diagnostics](../device-management/actions/collect-diagnostics.md). -- If you use co-management with tenant attach, you see the **Resource Explorer** and **Device Inventory** nodes.+## Related content - For Intune collected data, you see a **Device Inventory** tab. For Configuration Manager collected data, you see a **Resource Explorer** tab. Use the source that best fits your use case. In the future, use the Intune-based **Device Inventory**.+- [Intune data platform schema](../advanced-analytics/ref-data-platform-schema.md)+- [Device query](../advanced-analytics/device-query.md)+- [Device query for multiple devices](../advanced-analytics/device-query-multiple-devices.md) -- The client logs are at `C:\Program Files\Microsoft Device Inventory Agent\Logs`. You can also collect the logs by using the [Remote device action: collect diagnostics](../device-management/actions/collect-diagnostics.md). Use these logs to help troubleshoot.+<!--Intune admin center links--> -## Related content+[Microsoft Intune admin center]: https://go.microsoft.com/fwlink/?linkid=2109431 -- [Intune Data Platform Schema and property info](../advanced-analytics/ref-data-platform-schema.md) -<!--links-->+<!--Intune roles--> -[Microsoft Intune admin center]: https://go.microsoft.com/fwlink/?linkid=2109431\ No newline at end of file+[Custom role]: ../fundamentals/role-based-access-control/create-custom-role.md\ No newline at end of file