Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Azure Automation

Complete Guide to Automating Microsoft Intune Daily Tasks with Graph X-Ray

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Graph X-Ray helps you discover how the Intune admin center talks to Microsoft Graph; it does not turn portal clicks into production automation by itself. Use it to capture an operation, identify its endpoint, method, payload and permissions, then rewrite the result against documented Microsoft Graph APIs with least privilege, paging, retries, logging and safety controls.

This workflow is useful for inventory reports, compliance checks, application-status reviews and carefully governed device actions. Treat every captured request as a prototype until you have verified its API version, support status and permissions in Microsoft’s documentation.

What Graph X-Ray solves

An Intune page can make a task look simple while hiding several API calls. Graph X-Ray exposes the Microsoft Graph traffic generated by actions in supported Microsoft portals and can show the URL, HTTP method, request body and generated code. That closes the gap between a visible portal operation and a repeatable script.

Typical investigations include managed-device exports, stale-device reports, noncompliance reviews, application deployment failures, policy assignments, Intune script inventories and remote actions such as sync or restart. Discovery is not approval: wiping, retiring, deleting or broadly assigning resources requires explicit targeting and change control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Graph X-Ray is—and is not

Graph X-Ray is a separate browser add-on, not the Microsoft Graph service and not an official Intune automation framework. The Microsoft Edge listing is the appropriate place to verify availability and current version; it reported version 1.1.10, updated April 8, 2026, when checked. Extension versions and behavior can change, so verify the listing before deployment: official Edge listing.

A captured call may use Microsoft Graph beta, an internal portal route, transient headers, asynchronous follow-up requests or undocumented parameters. It may change independently of the portal UI. Use the Intune Graph documentation and the relevant API reference as the production authority. The 2024 walkthrough demonstrates the basic Intune workflow and lists PowerShell, Go, C#, Java, JavaScript and Objective-C output formats, but generated code still needs engineering review: walkthrough.

Prerequisites and a safe lab

  • An Intune tenant with the required licensing. Microsoft documents Intune Graph access for standalone Intune deployments; hybrid MDM deployments are not supported by the Intune Graph API overview: API overview.
  • A test tenant or tightly scoped test group, plus a dedicated administrator or application identity.
  • PowerShell 7 or later for new work. The older walkthrough lists PowerShell 5.1 as an SDK minimum, but it recommends PowerShell 7 or later.
  • The Microsoft Graph PowerShell SDK, source control, protected logging and a documented rollback or recovery plan.
  • Security approval for an extension that observes privileged portal traffic. Never share captured cookies, tokens, authorization headers or unredacted device data.

Install the SDK for your user profile:

Install-Module Microsoft.Graph -Scope CurrentUser

For a first, read-only investigation, sign in interactively with only the scopes required by the endpoint. The following scopes are illustrative, not universal:

Connect-MgGraph -Scopes `
    "DeviceManagementManagedDevices.Read.All", `
    "DeviceManagementApps.Read.All"

Check the endpoint’s API reference before granting consent. Delegated permissions act as the signed-in operator and suit interactive tools. Application permissions suit scheduled jobs, but require application consent, careful secret or certificate management and appropriate Intune RBAC. Neither permission model makes a destructive operation safe automatically.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Capture one Intune operation

  1. Open the Intune admin center and sign in with the test identity.
  2. Open browser developer tools and select the Graph X-Ray panel or extension interface.
  3. Clear the existing capture session so unrelated requests do not obscure the operation.
  4. Perform one deliberate action. The 2024 example uses Apps > All apps; labels and layout may differ in the current portal.
  5. Locate the request that corresponds to the action. A single click can create several calls, including metadata queries, the mutation itself and status polling.
  6. Record the HTTP method, complete URL, API version, query parameters, JSON body, response shape, permission requirements and whether the request is read-only or mutating.
  7. Copy the generated PowerShell only as a starting point. Save the request details in source control after removing tenant-specific secrets and personal data.

Do not assume the largest response is the important one. Follow the sequence and determine whether the portal accepted a job that completes later. A successful HTTP response can mean “queued” rather than “finished.”

Turn captured code into production PowerShell

Verify the contract first

Check whether the resource and operation exist in Microsoft Graph v1.0, whether the documented request and response schemas match, and which delegated and application permissions are supported. Use v1.0 for production when it provides the required behavior. If beta is unavoidable, isolate it in a clearly marked function, add regression tests and monitor Microsoft Graph change notices. Never change beta to v1.0 mechanically.

Remove browser-only details

Discard cookies, anti-forgery values, correlation IDs, portal telemetry headers and copied access tokens. Parameterize device, application, policy and group IDs. Store secrets in an approved identity system, not in a script or repository. Prefer an SDK cmdlet when it is stable and discoverable; use Invoke-MgGraphRequest for an operation that is not conveniently exposed by a cmdlet.

Use a documented, testable request

param(
    [string]$OutputPath = ".managed-devices.json"
)

$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices"

try {
    $response = Invoke-MgGraphRequest -Method GET -Uri $uri -OutputType PSObject
    $response.value |
        ConvertTo-Json -Depth 20 |
        Set-Content -Path $OutputPath -Encoding utf8
    Write-Host "Exported managed-device data to $OutputPath"
}
catch {
    Write-Error "Managed-device query failed: $($_.Exception.Message)"
    throw
}

This compact example is suitable only after you have confirmed that the selected resource is available in v1.0 and that the signed-in identity has the required permission. Tenant-scale jobs also need paging, throttling control and structured logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Retrieve every page

Graph collections commonly return an @odata.nextLink. Stop only when that property is absent:

function Get-GraphCollection {
    param([Parameter(Mandatory)][string]$Uri)

    $items = [System.Collections.Generic.List[object]]::new()
    do {
        $page = Invoke-MgGraphRequest -Method GET -Uri $Uri -OutputType PSObject
        foreach ($item in $page.value) { $items.Add($item) }
        $Uri = $page.'@odata.nextLink'
    } while ($Uri)
    return $items
}

Verify response property names and SDK behavior for the endpoint you selected before standardizing this function.

Useful daily automations

Managed-device inventory

Query device name, operating system and version, user association, last check-in, compliance state, enrollment profile, management agent and identifiers that the endpoint actually returns. Export CSV for operators or JSON for downstream systems, include a UTC timestamp and tolerate null properties. Filter at the API where supported instead of downloading an entire tenant unnecessarily.

Noncompliance and stale-device reporting

  1. Retrieve managed devices with the documented read permission.
  2. Select devices whose state is noncompliant, unknown or unavailable, and identify stale last-check-in times according to your policy.
  3. Export a report and send it to an operations channel or ticketing system.
  4. Keep reporting separate from remediation. Do not wipe or retire a device solely because a report contains it.

Application deployment status

Compare intended assignments with observed installation and failure states. An assignment proves targeting, not successful installation on every device. Investigate failed installs, devices that have not checked in and deployments that remain pending. Microsoft documents application management and status operations in its Intune overview: Intune concepts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Policy and assignment validation

For configuration-as-code, query for an equivalent policy before creating one, match stable IDs rather than display names alone, update only approved properties, check for duplicate assignments and record policy and assignment IDs. Use an exclusion group in testing. Replaying a portal request is not a substitute for version control, review and idempotent desired-state logic.

Controlled remote actions

Sync, restart, retire and wipe operations are mutating and may be irreversible. Require an explicit device-ID allowlist, display the target count, provide a dry-run or -WhatIf mode, log operator, time, action and result, rate-limit execution and require a ticket or approval for production. Separate target discovery from action execution and explain recovery limits to approvers.

Paging, throttling and idempotency

Handle HTTP 429 responses by honoring Retry-After when present, applying bounded exponential backoff with jitter and reducing concurrency. Cache stable data and avoid repeated full-tenant scans. Log request correlation information that is safe to retain, status codes, retry counts and elapsed time.

Design recurring jobs to converge safely: query before creating, compare immutable identifiers, update only changed values, treat “already exists” as a controlled state and persist operation results. A daily run should be safe to repeat after a timeout or partial failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scheduling and identity choices

Option Best fit Trade-off
Local scheduled task Small, operator-owned jobs Weak central monitoring and workstation dependency
Azure Automation Scheduled PowerShell runbooks, managed identities and job history Runtime, module and Azure governance overhead
Azure Functions Event-driven or API-backed automation Application deployment and observability complexity
Logic Apps Approvals, notifications, tickets and connector orchestration Per-action costs and less convenient high-volume processing
CI/CD pipeline Reviewed configuration-as-code changes Requires pipeline identity and release controls

For unattended execution, prefer managed identities or certificates over stored passwords and client secrets. Scope the application’s Graph permissions and Intune RBAC to the smallest practical surface.

Troubleshoot common failures

  • 401 Unauthorized: reconnect, check token audience and confirm the required delegated or application permission.
  • 403 Forbidden: verify admin consent, Intune RBAC role and scope; a valid token alone does not grant management rights.
  • 404 Not Found: confirm the resource path, API version and tenant capability. The portal may be using an internal route.
  • 400 Bad Request: compare JSON property names, required fields, enum values and content type with the documented schema.
  • 409 Conflict: handle existing resources, concurrent updates or assignment conflicts explicitly.
  • 429 Too Many Requests: honor retry guidance, back off and lower concurrency.
  • Empty or incomplete results: follow @odata.nextLink, check filters and allow for eventual consistency.
  • Missing SDK cmdlet: update or install the relevant Graph submodule, or use Invoke-MgGraphRequest after validating the REST operation.
  • Action appears unfinished: inspect follow-up status calls; acceptance of an asynchronous request is not completion.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When another tool is better

Use Graph Explorer to test an individual request interactively, not for unattended production jobs. The Graph PowerShell SDK is the default choice for PowerShell administrators; raw REST through Invoke-MgGraphRequest is useful when a cmdlet is unavailable.

Check native Intune dynamic groups, assignment filters, compliance policies, remediations, reports and built-in device actions before writing custom code. Native desired-state features avoid custom authentication and maintenance. Choose Azure Automation, Functions or Logic Apps only when scheduling, events, approvals or integrations justify their operational cost.

Do not use Graph X-Ray when the captured request is undocumented and unstable, the required permission is excessively broad, a destructive workflow lacks approval controls or organizational policy prohibits extensions in privileged sessions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Licensing and operating cost

Graph access does not remove the requirement for appropriate Intune licensing. Microsoft’s U.S. pricing page showed, in August 2026, Intune Plan 2 at $4.00 per user/month, Intune Suite at $10.00 and Remote Help at $3.50, with Microsoft 365 E3 at $39.00 and E5 at $60.00 per user/month when paid yearly (E5 without Teams was listed at $51.45). Prices, agreements, geography and July 2026 entitlement changes vary; verify the customer’s agreement at Microsoft Intune pricing. Do not buy an add-on merely to use Graph X-Ray or the SDK if existing licensing already covers the required Intune capability.

Production checklist

  • Use a test tenant or controlled group first.
  • Map the captured call to a documented endpoint and verify v1.0 or isolate beta code.
  • Record delegated and application permissions, Intune RBAC requirements and consent status.
  • Parameterize IDs and remove cookies, tokens and portal-only headers.
  • Implement pagination, 429 handling, bounded retries and structured logging.
  • Add dry-run, allowlist, approval and target-count checks for mutations.
  • Make recurring changes idempotent and keep scripts in reviewable source control.
  • Protect identities, certificates, logs and exported device data.
  • Monitor schedules and document rollback, recovery and asynchronous completion behavior.

Microsoft’s sample repositories are useful starting points, but samples can read, modify or delete tenant data and should be tested in a nonproduction tenant: PowerShell Intune samples and Microsoft Graph Intune samples.

Frequently Asked Questions

Is Graph X-Ray an official Microsoft Intune automation product?

No. It is a separate browser add-on that helps reveal Graph requests. Production automation should use documented Microsoft Graph contracts, reviewed permissions and operational safeguards.

Can I use a captured beta request in production?

Only when no supported v1.0 operation meets the requirement, and then isolate the beta dependency, test it and monitor for changes. Never promote it automatically.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a 200 response prove a wipe, restart or sync finished?

No. Intune may accept or queue an asynchronous operation. Follow the documented status behavior before reporting completion.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.