Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesGraph X-Ray helps you discover how the Intune admin center talks to Microsoft Graph; it does not turn portal clicks into production automation by itself. Use it to capture an operation, identify its endpoint, method, payload and permissions, then rewrite the result against documented Microsoft Graph APIs with least privilege, paging, retries, logging and safety controls.
This workflow is useful for inventory reports, compliance checks, application-status reviews and carefully governed device actions. Treat every captured request as a prototype until you have verified its API version, support status and permissions in Microsoft’s documentation.
What Graph X-Ray solves
An Intune page can make a task look simple while hiding several API calls. Graph X-Ray exposes the Microsoft Graph traffic generated by actions in supported Microsoft portals and can show the URL, HTTP method, request body and generated code. That closes the gap between a visible portal operation and a repeatable script.
Typical investigations include managed-device exports, stale-device reports, noncompliance reviews, application deployment failures, policy assignments, Intune script inventories and remote actions such as sync or restart. Discovery is not approval: wiping, retiring, deleting or broadly assigning resources requires explicit targeting and change control.
Recommended Free Tools
#1 Best Overall
What Graph X-Ray is—and is not
Graph X-Ray is a separate browser add-on, not the Microsoft Graph service and not an official Intune automation framework. The Microsoft Edge listing is the appropriate place to verify availability and current version; it reported version 1.1.10, updated April 8, 2026, when checked. Extension versions and behavior can change, so verify the listing before deployment: official Edge listing.
A captured call may use Microsoft Graph beta, an internal portal route, transient headers, asynchronous follow-up requests or undocumented parameters. It may change independently of the portal UI. Use the Intune Graph documentation and the relevant API reference as the production authority. The 2024 walkthrough demonstrates the basic Intune workflow and lists PowerShell, Go, C#, Java, JavaScript and Objective-C output formats, but generated code still needs engineering review: walkthrough.
Prerequisites and a safe lab
- An Intune tenant with the required licensing. Microsoft documents Intune Graph access for standalone Intune deployments; hybrid MDM deployments are not supported by the Intune Graph API overview: API overview.
- A test tenant or tightly scoped test group, plus a dedicated administrator or application identity.
- PowerShell 7 or later for new work. The older walkthrough lists PowerShell 5.1 as an SDK minimum, but it recommends PowerShell 7 or later.
- The Microsoft Graph PowerShell SDK, source control, protected logging and a documented rollback or recovery plan.
- Security approval for an extension that observes privileged portal traffic. Never share captured cookies, tokens, authorization headers or unredacted device data.
Install the SDK for your user profile:
Install-Module Microsoft.Graph -Scope CurrentUser
For a first, read-only investigation, sign in interactively with only the scopes required by the endpoint. The following scopes are illustrative, not universal:
Connect-MgGraph -Scopes `
"DeviceManagementManagedDevices.Read.All", `
"DeviceManagementApps.Read.All"
Check the endpoint’s API reference before granting consent. Delegated permissions act as the signed-in operator and suit interactive tools. Application permissions suit scheduled jobs, but require application consent, careful secret or certificate management and appropriate Intune RBAC. Neither permission model makes a destructive operation safe automatically.
Capture one Intune operation
- Open the Intune admin center and sign in with the test identity.
- Open browser developer tools and select the Graph X-Ray panel or extension interface.
- Clear the existing capture session so unrelated requests do not obscure the operation.
- Perform one deliberate action. The 2024 example uses Apps > All apps; labels and layout may differ in the current portal.
- Locate the request that corresponds to the action. A single click can create several calls, including metadata queries, the mutation itself and status polling.
- Record the HTTP method, complete URL, API version, query parameters, JSON body, response shape, permission requirements and whether the request is read-only or mutating.
- Copy the generated PowerShell only as a starting point. Save the request details in source control after removing tenant-specific secrets and personal data.
Do not assume the largest response is the important one. Follow the sequence and determine whether the portal accepted a job that completes later. A successful HTTP response can mean “queued” rather than “finished.”
Turn captured code into production PowerShell
Verify the contract first
Check whether the resource and operation exist in Microsoft Graph v1.0, whether the documented request and response schemas match, and which delegated and application permissions are supported. Use v1.0 for production when it provides the required behavior. If beta is unavoidable, isolate it in a clearly marked function, add regression tests and monitor Microsoft Graph change notices. Never change beta to v1.0 mechanically.
Rank #2
Remove browser-only details
Discard cookies, anti-forgery values, correlation IDs, portal telemetry headers and copied access tokens. Parameterize device, application, policy and group IDs. Store secrets in an approved identity system, not in a script or repository. Prefer an SDK cmdlet when it is stable and discoverable; use Invoke-MgGraphRequest for an operation that is not conveniently exposed by a cmdlet.
Use a documented, testable request
param(
[string]$OutputPath = ".managed-devices.json"
)
$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices"
try {
$response = Invoke-MgGraphRequest -Method GET -Uri $uri -OutputType PSObject
$response.value |
ConvertTo-Json -Depth 20 |
Set-Content -Path $OutputPath -Encoding utf8
Write-Host "Exported managed-device data to $OutputPath"
}
catch {
Write-Error "Managed-device query failed: $($_.Exception.Message)"
throw
}
This compact example is suitable only after you have confirmed that the selected resource is available in v1.0 and that the signed-in identity has the required permission. Tenant-scale jobs also need paging, throttling control and structured logs.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRetrieve every page
Graph collections commonly return an @odata.nextLink. Stop only when that property is absent:
function Get-GraphCollection {
param([Parameter(Mandatory)][string]$Uri)
$items = [System.Collections.Generic.List[object]]::new()
do {
$page = Invoke-MgGraphRequest -Method GET -Uri $Uri -OutputType PSObject
foreach ($item in $page.value) { $items.Add($item) }
$Uri = $page.'@odata.nextLink'
} while ($Uri)
return $items
}
Verify response property names and SDK behavior for the endpoint you selected before standardizing this function.
Useful daily automations
Managed-device inventory
Query device name, operating system and version, user association, last check-in, compliance state, enrollment profile, management agent and identifiers that the endpoint actually returns. Export CSV for operators or JSON for downstream systems, include a UTC timestamp and tolerate null properties. Filter at the API where supported instead of downloading an entire tenant unnecessarily.
Noncompliance and stale-device reporting
- Retrieve managed devices with the documented read permission.
- Select devices whose state is noncompliant, unknown or unavailable, and identify stale last-check-in times according to your policy.
- Export a report and send it to an operations channel or ticketing system.
- Keep reporting separate from remediation. Do not wipe or retire a device solely because a report contains it.
Application deployment status
Compare intended assignments with observed installation and failure states. An assignment proves targeting, not successful installation on every device. Investigate failed installs, devices that have not checked in and deployments that remain pending. Microsoft documents application management and status operations in its Intune overview: Intune concepts.
Policy and assignment validation
For configuration-as-code, query for an equivalent policy before creating one, match stable IDs rather than display names alone, update only approved properties, check for duplicate assignments and record policy and assignment IDs. Use an exclusion group in testing. Replaying a portal request is not a substitute for version control, review and idempotent desired-state logic.
Controlled remote actions
Sync, restart, retire and wipe operations are mutating and may be irreversible. Require an explicit device-ID allowlist, display the target count, provide a dry-run or -WhatIf mode, log operator, time, action and result, rate-limit execution and require a ticket or approval for production. Separate target discovery from action execution and explain recovery limits to approvers.
Paging, throttling and idempotency
Handle HTTP 429 responses by honoring Retry-After when present, applying bounded exponential backoff with jitter and reducing concurrency. Cache stable data and avoid repeated full-tenant scans. Log request correlation information that is safe to retain, status codes, retry counts and elapsed time.
Design recurring jobs to converge safely: query before creating, compare immutable identifiers, update only changed values, treat “already exists” as a controlled state and persist operation results. A daily run should be safe to repeat after a timeout or partial failure.
Scheduling and identity choices
| Option | Best fit | Trade-off |
|---|---|---|
| Local scheduled task | Small, operator-owned jobs | Weak central monitoring and workstation dependency |
| Azure Automation | Scheduled PowerShell runbooks, managed identities and job history | Runtime, module and Azure governance overhead |
| Azure Functions | Event-driven or API-backed automation | Application deployment and observability complexity |
| Logic Apps | Approvals, notifications, tickets and connector orchestration | Per-action costs and less convenient high-volume processing |
| CI/CD pipeline | Reviewed configuration-as-code changes | Requires pipeline identity and release controls |
For unattended execution, prefer managed identities or certificates over stored passwords and client secrets. Scope the application’s Graph permissions and Intune RBAC to the smallest practical surface.
Troubleshoot common failures
- 401 Unauthorized: reconnect, check token audience and confirm the required delegated or application permission.
- 403 Forbidden: verify admin consent, Intune RBAC role and scope; a valid token alone does not grant management rights.
- 404 Not Found: confirm the resource path, API version and tenant capability. The portal may be using an internal route.
- 400 Bad Request: compare JSON property names, required fields, enum values and content type with the documented schema.
- 409 Conflict: handle existing resources, concurrent updates or assignment conflicts explicitly.
- 429 Too Many Requests: honor retry guidance, back off and lower concurrency.
- Empty or incomplete results: follow
@odata.nextLink, check filters and allow for eventual consistency. - Missing SDK cmdlet: update or install the relevant Graph submodule, or use
Invoke-MgGraphRequestafter validating the REST operation. - Action appears unfinished: inspect follow-up status calls; acceptance of an asynchronous request is not completion.
When another tool is better
Use Graph Explorer to test an individual request interactively, not for unattended production jobs. The Graph PowerShell SDK is the default choice for PowerShell administrators; raw REST through Invoke-MgGraphRequest is useful when a cmdlet is unavailable.
Rank #4
Check native Intune dynamic groups, assignment filters, compliance policies, remediations, reports and built-in device actions before writing custom code. Native desired-state features avoid custom authentication and maintenance. Choose Azure Automation, Functions or Logic Apps only when scheduling, events, approvals or integrations justify their operational cost.
Do not use Graph X-Ray when the captured request is undocumented and unstable, the required permission is excessively broad, a destructive workflow lacks approval controls or organizational policy prohibits extensions in privileged sessions.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Licensing and operating cost
Graph access does not remove the requirement for appropriate Intune licensing. Microsoft’s U.S. pricing page showed, in August 2026, Intune Plan 2 at $4.00 per user/month, Intune Suite at $10.00 and Remote Help at $3.50, with Microsoft 365 E3 at $39.00 and E5 at $60.00 per user/month when paid yearly (E5 without Teams was listed at $51.45). Prices, agreements, geography and July 2026 entitlement changes vary; verify the customer’s agreement at Microsoft Intune pricing. Do not buy an add-on merely to use Graph X-Ray or the SDK if existing licensing already covers the required Intune capability.
Production checklist
- Use a test tenant or controlled group first.
- Map the captured call to a documented endpoint and verify v1.0 or isolate beta code.
- Record delegated and application permissions, Intune RBAC requirements and consent status.
- Parameterize IDs and remove cookies, tokens and portal-only headers.
- Implement pagination, 429 handling, bounded retries and structured logging.
- Add dry-run, allowlist, approval and target-count checks for mutations.
- Make recurring changes idempotent and keep scripts in reviewable source control.
- Protect identities, certificates, logs and exported device data.
- Monitor schedules and document rollback, recovery and asynchronous completion behavior.
Microsoft’s sample repositories are useful starting points, but samples can read, modify or delete tenant data and should be tested in a nonproduction tenant: PowerShell Intune samples and Microsoft Graph Intune samples.
Frequently Asked Questions
Is Graph X-Ray an official Microsoft Intune automation product?
No. It is a separate browser add-on that helps reveal Graph requests. Production automation should use documented Microsoft Graph contracts, reviewed permissions and operational safeguards.
Can I use a captured beta request in production?
Only when no supported v1.0 operation meets the requirement, and then isolate the beta dependency, test it and monitor for changes. Never promote it automatically.
Does a 200 response prove a wipe, restart or sync finished?
No. Intune may accept or queue an asynchronous operation. Follow the documented status behavior before reporting completion.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




