Data collection in Intune - Microsoft Intune (2024)

  • Article

When users enroll their corporate or personal devices with Intune, Intune collects, processes, and shares some personal data to support business operations, conduct business with the customer and to support the service. Intune collects personal data from the following sources:

  • The administrators use of the Intune in the Microsoft Intune admin center.
  • End-user devices (when devices are enrolled for Intune management and during usage).
  • Customer accounts at third party services (per admin's instructions).
  • Diagnostic, performance, and usage information.

From these sources, Intune collects information that falls into the following two categories: required, optional. Each category is divided into customer data, personal data, diagnostic data, and service-generated data.

Required data

Data in the required category consists of data in the default feature set that is necessary to make our service work as expected by the customer. Most of the data collected by Intune is required data. This data is tied to a user, device, or application and is essential to the nature of management. The data collected contains both personal data and non-personal data. Personal data includes identifiable data that may directly identify the end user, or pseudonymized data with a unique identifier generated by the system that's used to deliver the enterprise service to users, support data, and account data. Non-personal data includes service-generated system metadata and organizational/tenant information. Intune also collects access control data to manage access to administrative roles and functions through features like Role Based Access Control.

Required data collected by Intune may include, but isn't limited to:

CategoryDataMAM workload 1
Access control informationPrivate keys for certificatesNo
Static authenticators (customer's password)No
Admin and account informationActive Directory ID of each customer IT adminYes
Admin user first name and last nameYes
Admin user nameYes
Email address of account ownerYes
Payment data for customer billingYes
Phone numberYes
Subscription keyYes
UPN (email)Yes
Admin created data, like:Compliance policiesNo
Group policyNo
Line-of-Business (LOB) applicationYes
PowerShell scriptsNo
Profile namesYes
Admin usage data from across all Intune tenants (for example, admin controls selected when interacting with the Admin console)Yes
Application inventory, like:app IDYes (Managed apps only)
app nameYes (Managed apps only)
installation locationNo
sizeNo
versionYes (Managed apps only)
Note: Application inventory data is only collected when marked by the Admin as a corporate-owned device or the compliant app feature is turned on.
Audit log information, including data about the following activitiesAssignYes
CreateYes
DeleteYes
ManageYes
Remote tasksYes
Update (edit)Yes
Customer third party tenant IDs (like Apple ID)No
Device DataAccount IDYes
AppleID for iOS/iPadOS devicesNo
Microsoft Entra device IDYes (If device is Microsoft Entra joined)
Intune device IDYes (If device is MDM enrolled with Intune)
Device storage spaceNo
EAS device IDNo
Intune device management IDYes (If device is MDM enrolled with Intune)
Location (corporate devices only)No
Mac Address for Mac devicesNo
Network informationNo
Platform-specific IDsNo
Tenant IDYes
Windows ID for Windows devicesNo
Hardware inventory informationDevice nameYes (Device Friendly Name)
Device typeYes
ICCIDNo
IMEI numberNo
IP addressNo
ManufacturerYes
ModelYes
Operating systemYes
Operating system versionYes
Serial numberNo
Wi-Fi MacAddressNo
Managed application informationMicrosoft Entra device IDYes (If device is Microsoft Entra joined)
Device enrollment statusYes
Device health statusYes (Includes threat status if a Mobile Threat Defense connector is configured)
Encryption keysYes
Intune device management IDYes (If device is MDM enrolled with Intune)
Last application check-in date/timeYes
Managed application device tagYes
Managed application IDYes
Managed application SDK versionYes
Managed application versionYes
MAM enrollment data/timeYes
MAM enrollment statusYes
Support informationContact information (name, phone number, email address)No
Email discussions with Microsoft support, product, and/or customer experience team membersNo
Tenant account information (this data is available from the Microsoft Intune admin centerinstalledDeviceCount: The number of devices on which the application is installed.Yes
Number of devices or users enrolledNo
Number of identified device platformsNo
Number of installed devicesNo
notApplicableDeviceCount: The number of devices for which the application isn't applicable.No
notInstalledDeviceCount: The number of devices for which the application is applicable but not installed.No
pendingInstallDeviceCount: The number of devices for which the application is applicable and installation is pending.No
User informationOwner name/user display (the Azure-registered name of the user as identified by AzureUserID)Yes
Phone numberNo
Third-party user identifies (like AppleID)No
User Principal Name or email addressYes

1 Intune Mobile Application Management (MAM) can be deployed independent of other Intune workloads. For customers only using Intune MAM, this column identifies which required data is collected.

Optional data

Data in the required category consists of data in the default feature set that is necessary to make our service work as expected by the customer.

Your organization may enable optional features within Intune which enable collection of additional information from devices:

  • Device query for Corporate-owned Windows Devices

    When a customer enables Device query, the admin can query device details such as File Name and File Path. For a complete list of data, see Intune data platform schema.

Customers can control the collection of pseudonymized diagnostics and telemetry data from Intune components installed on their devices. We think there are compelling reasons for people to share this optional data as it helps Microsoft improve the reliability and performance of its products and we understand the importance of providing users the opportunity to make these choices for themselves.

Examples of the optional data fall into the following categories as defined by the ISO/IEC 19944-1:2020 Information technology - Cloud computing - Cloud services and devices: Data flow, data categories:

  • Details about the device, its configuration and connectivity capabilities, and status.
  • Details about the usage of the device, operating system, applications, and services.
  • Details about the health of the device, operating system, apps, and drivers.
  • Software installation and update information on the device.

Certain End User Data or Content is never Collected

Intune doesn't collect nor allow an Admin to see the following data:

  • An end users’ calling or web browsing history
  • Personal email
  • Text messages
  • Contacts
  • Passwords to personal accounts
  • Calendar events
  • Photos, including those in a photo app or camera

For more information, see Getting started enrolling devices.

For more information on the data types and definition, see How Microsoft categorizes data for online services.

Next steps

Learn more about how Intune stores and processes and shares personal data.

Data collection in Intune - Microsoft Intune (2024)
Top Articles
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 6053

Rating: 4.3 / 5 (64 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.