Recommended Free Tools
Use Microsoft Graph report export jobs to automate Intune’s device-level FirewallStatus data. The workflow is asynchronous: authenticate, create an export job, poll it until completion, download the temporary ZIP, and parse the CSV or JSON inside. The report includes firewall state, device identifiers, operating-system and management data, reporting freshness, and user fields such as UPN and UserName.
What the FirewallStatus report provides
FirewallStatus is a posture dataset for Windows devices that are enrolled and reporting through Intune. It is not a rule-by-rule policy dump, packet log, or replacement for Microsoft Defender telemetry and Windows event logs. The current Intune report catalog lists these properties: Microsoft’s available-report reference.
| Property | Use |
|---|---|
FirewallStatus |
Reported firewall state. Inspect values returned by your tenant before hard-coding comparisons. |
DeviceName |
Managed device name. |
DeviceId |
Device identifier returned by the report; use it as a stable remediation key. |
UPN |
User principal name associated with the device record. It can be blank or unsuitable as an owner key for shared devices. |
UserName |
User-name field; do not assume it is interchangeable with UPN. |
_ManagedBy |
Management-authority information. |
_OS |
Operating-system information. |
LastReportedDateTime |
Freshness indicator. An old timestamp is stale data, not proof that the firewall is disabled. |
ReferenceId |
Report/reference metadata. |
The catalog documents filtering by FirewallStatus; supported filters are report-specific, so do not assume every column can be filtered.
Prerequisites and permissions
- An active Intune entitlement in the tenant. A user license, app permission, and service-principal authorization are separate requirements.
- An Entra identity and a Microsoft Graph token. Personal Microsoft accounts are not supported for these Intune operations.
- For unattended jobs, an app registration with application permissions and a certificate or approved workload identity. Do not put client secrets in scripts or scheduled-task arguments.
- Start by evaluating the least-privileged application permission,
DeviceManagementManagedDevices.Read.All, identified by the Intune report catalog. Graph export-job documentation also lists delegated or application alternatives includingDeviceManagementConfiguration.Read.All,DeviceManagementConfiguration.ReadWrite.All,DeviceManagementApps.Read.All,DeviceManagementApps.ReadWrite.All, andDeviceManagementManagedDevices.ReadWrite.All. Grant only what the selected authentication model and tenant require, then obtain admin consent.
See the permission and licensing notes in the export-job list documentation and export-job retrieval documentation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- The Instant On Secure Gateway SG1004 is a great device for small and medium businesses to safeguard their business network from external threats. Support for up to 940Mbps of network throughput is achieved with hardware acceleration and all security settings in active mode. Ideal for smaller footprints or lower ISP bandwidth, the SG1004 keeps your employees, business, and customers safe from cyber threats.
- EASY SET UP AND MANAGEMENT: Deploy, manage, and monitor your Instant On Secure Gateways and other Instant On hardware from any device using the Instant On mobile app or web browser –no subscription required. Guided step-by-step instructions to install devices and get your network up and running quickly. Quickly define firewall policies for the site, network, client, or applications from the management app.
- CONFIGURATION: The space-efficient gateway can be mounted on a wall or kept under a table making the deployment versatile. 4-ports of 1GbE are on the back of the device and comes with an external power supply.
- SECURITY WITHOUT COMPROMISE: Thanks to a hardware-accelerated firewall, IDS/IPS, and DPI the Instant On SG1004 achieves up to 940Mbps of throughput even over IPsec or site-to-site VPN tunnels. Easily provide enterprise-grade security for your small or medium business at an affordable cost.
- WARRANTY & SUPPORT: Manage your networks with peace of mind thanks to a 2-year warranty and chat support for the life of the product
Test the export with Graph Explorer
Graph Explorer is useful for confirming the report name, permissions, and returned schema. It is an interactive test tool, not a production scheduler. The August 28, 2024 HTMD walkthrough uses the beta create route:
POST https://graph.microsoft.com/beta/deviceManagement/reports/exportJobs
Authorization: Bearer <access-token>
Content-Type: application/json
{
"reportName": "FirewallStatus",
"format": "csv"
}
That walkthrough is documented at HTMD Blog. Save the response’s id; the job also exposes status and download metadata such as url, requestDateTime, and expirationDateTime.
Microsoft currently documents v1.0 list and get operations for export jobs:
Rank #2
- 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
- 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
- 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
- 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
- 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.
GET https://graph.microsoft.com/v1.0/deviceManagement/reports/exportJobs
GET https://graph.microsoft.com/v1.0/deviceManagement/reports/exportJobs/{deviceManagementExportJobId}
Because the original create example is beta while current documentation exposes v1.0 retrieval, test the create operation in your tenant and use the documented version that supports your report. A 404 can indicate an unsupported route, report name, or operation version.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Create a job with optional filtering
The minimal request exports all available rows. You can request JSON instead of CSV and, where supported, add a filter or selection. For example:
{
"reportName": "FirewallStatus",
"filter": "FirewallStatus eq 'Unhealthy'",
"format": "csv"
}
Validate the exact status strings by inspecting an unfiltered result first. Do not assume that values are universally named Healthy, Unhealthy, Enabled, or Disabled. The export-job model also includes select and localizationType; use selection to reduce payload when the tenant accepts it, and normalize localized display values before applying automation rules. JSON may suit structured pipelines, while CSV is convenient for tabular processing.
Rank #3
- CUSTOM IDENTIFIER: FIREYE E100 EB-700 D635151
Poll until the export is complete
Export creation is asynchronous. Poll the job by ID with a bounded delay; never run an uncontrolled tight loop.
GET https://graph.microsoft.com/v1.0/deviceManagement/reports/exportJobs/{exportJobId}
Authorization: Bearer <access-token>
Accept: application/json
Handle notStarted and inProgress by waiting, stop on a completed state, and fail clearly on an error state. Status spelling can vary by service version, so log the returned value and code defensively. Microsoft describes the resource and its properties in the export-job resource reference.
PowerShell implementation pattern
The following uses Invoke-MgGraphRequest. Replace the authentication step with your approved certificate, workload-identity, or interactive sign-in process.
Rank #4
$graphBase = "https://graph.microsoft.com"
$createUri = "$graphBase/beta/deviceManagement/reports/exportJobs"
# Authenticate before this point, for example with Connect-MgGraph.
$body = @{
reportName = "FirewallStatus"
format = "csv"
} | ConvertTo-Json
$job = Invoke-MgGraphRequest -Method POST -Uri $createUri `
-Body $body -ContentType "application/json"
$jobId = $job.id
if (-not $jobId) { throw "The export response did not contain a job ID." }
$statusUri = "$graphBase/v1.0/deviceManagement/reports/exportJobs/$jobId"
$maxAttempts = 30
$delaySeconds = 10
$current = $null
for ($attempt = 1; $attempt -le $maxAttempts; $attempt++) {
Start-Sleep -Seconds $delaySeconds
$current = Invoke-MgGraphRequest -Method GET -Uri $statusUri
$status = [string]$current.status
if ($status -in @("completed", "complete")) { break }
if ($status -in @("failed", "error")) {
throw "FirewallStatus export failed. Job ID: $jobId; status: $status"
}
if ($attempt -eq $maxAttempts) {
throw "Timed out waiting for export job $jobId (last status: $status)."
}
}
if (-not $current.url) {
throw "Completed job returned no download URL. Job ID: $jobId"
}
$zipPath = Join-Path $env:TEMP "FirewallStatus-$jobId.zip"
Invoke-WebRequest -Uri $current.url -OutFile $zipPath
$extractPath = Join-Path $env:TEMP "FirewallStatus-$jobId"
Expand-Archive -Path $zipPath -DestinationPath $extractPath -Force
$inputFile = Get-ChildItem -Path $extractPath -File |
Where-Object { $_.Extension -in '.csv', '.json' } |
Select-Object -First 1
if (-not $inputFile) { throw "The ZIP contained no CSV or JSON report." }
if ($inputFile.Extension -eq '.csv') {
$rows = Import-Csv $inputFile.FullName
} else {
$rows = Get-Content $inputFile.FullName -Raw | ConvertFrom-Json
}
$rows | Group-Object FirewallStatus | Select-Object Name, Count
For production, add exponential backoff for transient Graph failures, honor HTTP 429 guidance, stream large downloads where practical, and write only non-sensitive diagnostics. Persist the job ID and execution timestamp rather than the signed URL.
Download, extract, and protect the result
When complete, the job’s url points to a ZIP containing CSV or JSON according to the requested format. The URL is temporary and should be treated as a secret-bearing credential while valid. Download promptly, check expirationDateTime, and never place the URL in pipeline logs, tickets, or telemetry. Store extracted files in a restricted temporary directory, limit retention of UPNs, and delete the archive and extracted data when processing finishes.
If the URL expires, query the job once more. If it is no longer usable, submit a new export job and download immediately; do not retry a stale signed URL indefinitely.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- Advanced Video Support & High-Resolution Display : Supports H.265/H.264 encoding and 4K video display via mainstream protocols. Features a 1280x800 resolution IPS touch screen for clear and detailed visuals. (Note: The product box and manual are generic and include all functions. Actual product functionality is as described)
- Comprehensive Cable Testing & Reporting : Equipped with RJ45 cable TDR testing for accurate cable quality assessment. Automatically detects and displays video signals, and generates detailed testing reports for quick diagnostics
- Dual Window Testing & Multi-Platform Display : Supports simultaneous testing of IP and analog cameras with dual-window functionality. Compatible with TesterPlay, Android devices, and PC displays for versatile monitoring and testing
- HDMI Output & Office Tools : Features HDMI output with 1080p resolution for high-quality video display. Includes quick office tools for viewing Excel, Word, and PPT documents, along with UTP cable testing capabilities
- Self-Updating Software & Connectivity Features : Allows customers to self-update software for the latest features. Built-in WiFi with hotspot functionality, IP discovery, shortcut buttons, and a user-friendly drop-down menu. Supports DC12V 2A and DC48V PoE power output for flexible power options
Turn rows into operational decisions
- Normalize column names and status values, especially when localization is enabled.
- Classify rows by firewall state and separately flag records whose
LastReportedDateTimeis stale. - Use
DeviceIdfor remediation joins; useUPNandUserNameas contextual identity fields, not guaranteed ownership proof. - Join to CMDB, ticketing, or inventory records only in access-controlled systems.
- Schedule snapshots outside peak administrative activity and retain only the history required for audit or trend analysis.
A blank UPN can be normal for shared devices or records without a current user association. It does not indicate an unhealthy firewall. Likewise, a recent unhealthy status is different from a device that simply has not reported recently.
Troubleshooting
| Symptom | Likely cause | Recovery |
|---|---|---|
| 401 Unauthorized | Expired token, wrong audience, or invalid credential | Acquire a Microsoft Graph token and verify its audience and lifetime. |
| 403 Forbidden | Missing permission, admin consent, blocked service principal, or insufficient authorization | Check the app’s delegated/application mode, grant the least privilege needed, and confirm tenant policy. |
| 404 Not Found | Unsupported API version, operation, or report name | Test the documented route and confirm FirewallStatus is available in the tenant. |
| 429 or 5xx | Throttling or transient service failure | Use bounded retries with backoff and preserve the job ID. |
| Job remains in progress | Service delay or transient processing issue | Poll at a fixed or increasing interval, then stop at a defined timeout. |
| Completed job has no URL | Incomplete response or service issue | Query the job again; if still absent, record the ID and retry with a new job. |
| Download fails | Temporary URL expired | Create a fresh export and download as soon as it completes. |
| Blank UPN | Shared device or no current user association | Report device identity separately and avoid UPN-only remediation. |
| Unexpected status values | Tenant or localization differences | Inspect returned values and normalize them before filtering. |
| Report appears stale | Device has not recently reported | Use LastReportedDateTime to separate stale data from an unhealthy state. |
Beta-to-v1.0 and tooling choices
The HTMD example is a useful beta-era demonstration, but it was published on August 28, 2024. Microsoft’s current documentation provides v1.0 list and get operations, so production code should isolate endpoint versions and test the create call in the target tenant rather than assuming beta behavior is permanent.
| Approach | Best fit | Trade-off |
|---|---|---|
| Raw Graph requests in PowerShell | Intune administrators, runbooks, rapid prototypes | You own authentication, retries, schema and version handling. |
| Microsoft Graph SDK | Typed applications and shared libraries | SDK surfaces can lag report operations; direct requests may still be needed. |
| Azure Automation | Scheduled PowerShell without a server | Requires Azure identity, runbook governance and cost review. |
| Azure Functions | Event-driven or scheduled multi-language jobs | Adds hosting and identity configuration. |
| Power BI | Historical dashboards after storing snapshots | Needs a retention layer and careful UPN access controls; it does not replace export jobs. |
| Manual Intune export | One-off investigations | No dependable scheduling or integration. |
For scheduled execution, Azure Automation is documented at Azure Automation, Azure Functions at Azure Functions, and Power BI at Power BI. Microsoft Defender for Endpoint can complement this report when you need security telemetry beyond Intune posture data; it is not a drop-in replacement for the Graph export.
Security and privacy checklist
- Use least-privilege Graph permissions and require admin consent through your normal change process.
- Prefer certificates or workload identity for unattended jobs; rotate credentials and keep private keys out of source control.
- Redact UPNs and usernames from ordinary logs and dashboards.
- Protect ZIP files, extracted reports, and historical snapshots with access controls and defined retention.
- Never log signed download URLs.
- Alert on actionable conditions, such as a recent unhealthy state or stale reporting, rather than treating every missing user field as a firewall failure.
The Bottom Line
For repeatable Intune firewall posture reporting, create a FirewallStatus Graph export job, poll it with a timeout, download the expiring ZIP immediately, and process the returned device and identity fields with least-privilege access and explicit stale-data handling.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




