Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To compare Microsoft Entra-joined and Microsoft Entra hybrid-joined Windows devices, query the IntuneDevices table in the Log Analytics workspace receiving Intune diagnostic data. The table’s JoinType field is the starting point—but first check the table, schema, and actual values in your tenant. A row count is not automatically a device count, and this report covers records ingested into that workspace, not necessarily every current Intune device.
Older documentation and existing data may use “Azure AD joined” and “Hybrid Azure AD joined.” Microsoft Entra ID is the current name for Azure Active Directory; validate which labels your table contains before filtering.
What this report tells you—and what it does not
This report helps answer an operational question: among devices represented in Intune diagnostic data, which are cloud-joined and which are hybrid-joined? It can help track a move away from on-premises Active Directory dependencies, investigate unexpected join states, and build a Log Analytics workbook or export for migration planning.
Keep three separate concepts in view:
- Join type describes the device’s relationship to Microsoft Entra ID and, for hybrid join, on-premises Active Directory. Other states or blank values may also appear.
- Management state describes whether and how a device is managed—for example, through Intune, Configuration Manager, co-management, or another method. Join type alone does not identify the management authority.
- Reporting presence means a record arrived in the particular Log Analytics workspace and remains within its retention period. It does not prove that the record is a complete or real-time inventory of the tenant.
A hybrid-joined device is not necessarily co-managed, and an Intune-managed device may have a missing, delayed, or differently represented join value in diagnostic data.
#1 Best Overall
- Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.
- Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
Prerequisites and data path
The expected flow is Intune diagnostic settings → Log Analytics workspace → IntuneDevices table → KQL report. You need an Intune environment with relevant Windows devices, access to the diagnostic configuration and workspace Logs, and a workspace receiving the required Intune diagnostic data. Allow time for data to begin arriving after configuration. Historical records from before diagnostics were enabled should not be expected, and workspace retention limits how far back you can query.
An older HTMD tutorial lists IntuneAuditLogs, IntuneDeviceComplianceOrg, IntuneDevices, and IntuneOperationalLogs among relevant tables. Treat those names as a starting point, not a guarantee that every workspace has the same tables or schema. See the original HTMD KQL report for its 2022 examples.
1. Confirm that the table contains data
Open the relevant Log Analytics workspace in the Azure portal, select Logs, and run:
IntuneDevices
| take 10
If the query returns rows, the table is available and contains data in the selected time range. If it fails with “Failed to resolve table,” check that diagnostics are directed to this workspace, that the table name is available in its Tables pane, and that your account can access it. If the query succeeds but returns no rows, check the time picker, diagnostic configuration, ingestion, and whether devices have reported data yet.
2. Inspect the schema and join values
Do not assume that a query written in 2022 will match the current labels or columns in every tenant. Inspect the table schema:
Rank #2
- With 16 GB of memory, runs as many programs as you want without losing the execution
- The 13.5" 2256 x 1504 screen provides a great movie watching experience
- 512 GB SSD is enough to store your essential documents and files, favorite songs, movies and pictures
- 8 Hours battery run time helps you stay unwired and work longer non-stop
IntuneDevices
| getschema
Then enumerate values currently present in JoinType:
IntuneDevices
| summarize Rows=count() by JoinType
| order by Rows desc
This reveals spelling, capitalization, blank values, and categories you may not have anticipated. The table must contain a JoinType field for the examples below to work; confirm identifiers such as DeviceId before using them in a distinct-device or deduplication query.
3. Compare join categories
For a quick count of records by join type, use the values seen in the previous query. This example includes both legacy Azure AD labels and current Microsoft Entra labels:
IntuneDevices
| where JoinType in~ (
"Azure AD joined",
"Hybrid Azure AD joined",
"Microsoft Entra joined",
"Microsoft Entra hybrid joined"
)
| summarize Rows=count() by JoinType
| order by JoinType asc
in~ performs case-insensitive matching, but it does not make the labels universal: retain or change the listed values based on your tenant’s results. This query counts rows, not necessarily unique devices.
To group legacy and current labels into the two intended categories while keeping blanks and other values visible, use:
Rank #3
- A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
- WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
- A 13.8" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
- 20 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 20 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
- THE PORTS YOU NEED — Two USB-C / USB4[4] ports for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.
IntuneDevices
| extend NormalizedJoinType = case(
JoinType in~ ("Azure AD joined", "Microsoft Entra joined"),
"Microsoft Entra joined",
JoinType in~ ("Hybrid Azure AD joined", "Microsoft Entra hybrid joined"),
"Microsoft Entra hybrid joined",
isempty(JoinType),
"Blank or unknown",
"Other"
)
| summarize Rows=count() by NormalizedJoinType
| order by NormalizedJoinType asc
This is a defensive grouping method, not evidence that every listed value occurs in every environment. Compare the output with the unnormalized values so that an unexpected category is not hidden inside “Other.”
Free tools Windows power users keep installed
One-click scans. No signup required.
Rows versus unique devices
Repeated check-ins, diagnostic events, state changes, or duplicate records can make one device appear more than once. A row total can therefore describe ingested records rather than the device population. If getschema confirms that DeviceId exists and is a reliable key for your data, compare rows with distinct device IDs:
IntuneDevices
| summarize
Rows=count(),
Devices=dcount(DeviceId)
by JoinType
| order by Devices desc
dcount() is an approximate distinct count. If you need an exact figure, select the appropriate exact-count method for your reporting requirements and validate its performance on the workspace data. A device that changed join state may also appear under more than one category over a historical period, so define the time window and whether the question concerns records or the latest device state.
4. List device and user details
To inspect records from the last 30 days, project useful columns and sort the result:
IntuneDevices
| where TimeGenerated >= ago(30d)
| where JoinType in~ (
"Azure AD joined",
"Hybrid Azure AD joined",
"Microsoft Entra joined",
"Microsoft Entra hybrid joined"
)
| project TimeGenerated, DeviceName, UserName, DeviceState, JoinType
| order by JoinType asc, DeviceName asc
The original HTMD examples use DeviceName, UserName, and DeviceState for device details. Check getschema and adapt the projection if your table differs. TimeGenerated is the record’s event or ingestion timestamp in the workspace; it is not necessarily the device’s last Intune check-in time.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #4
- A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
- WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
- A 15" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
- 19 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 19 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
- Two USB-C / USB4[4] ports and a microSD card reader for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.
For a fixed audit period, use explicit dates, for example:
IntuneDevices
| where TimeGenerated between (datetime(2026-08-01) .. datetime(2026-08-18))
Adjust the range to the dates you actually need and to the data available under workspace retention.
Keep only the latest record per device
If the report needs one latest record per device rather than every record, and the schema confirms a stable DeviceId, use arg_max() to select the row with the latest TimeGenerated for each ID:
IntuneDevices
| where TimeGenerated >= ago(30d)
| summarize arg_max(TimeGenerated, *) by DeviceId
| project TimeGenerated, DeviceId, DeviceName, UserName, DeviceState, JoinType
| order by JoinType asc, DeviceName asc
Use this only when “latest record wins” fits the question and DeviceId is suitable. Without a dependable key, do not deduplicate by device name alone: names can change or be duplicated. A latest record in the selected window also does not prove the device is currently active or managed.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →5. Check unrecognized and blank values
Do not silently discard records that do not match the two expected categories. This query surfaces blank or other join-type values for review:
Best Value
- Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.
- Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
IntuneDevices
| where isempty(JoinType) or JoinType !in~ (
"Azure AD joined",
"Hybrid Azure AD joined",
"Microsoft Entra joined",
"Microsoft Entra hybrid joined"
)
| summarize Rows=count() by JoinType
| order by Rows desc
A blank or unexpected value is not proof of enrollment failure. It may reflect delayed or incomplete telemetry, a different device category, a schema change, or a state not represented by the two categories being compared.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Intune portal alternative
For a quick interactive lookup, the Intune admin center device list may expose a Join Type column; the original HTMD article describes adding it to the device list. Portal labels and layout can change, so use the current device-list column controls if the label or location differs. The portal is convenient for checking an individual device, while KQL is better suited to custom aggregation, historical analysis, workbooks, and export. The portal’s current inventory and Log Analytics’ retained diagnostic records may not match exactly.
| Method | Useful for | Trade-off |
|---|---|---|
| Intune device list | Fast interactive lookup | Less flexible for historical analysis and custom aggregation |
| Log Analytics KQL | Custom filters, trends, workbooks, and exports | Requires diagnostics, ingestion, permissions, retention, and schema checks |
| Microsoft Graph | Scheduled exports, integrations, reconciliation, and automation | Requires API permissions and code that handles pagination and throttling |
| Entra device inventory | Reviewing directory device identity and join state | Not necessarily equivalent to Intune management inventory |
Troubleshooting common results
- Table not found: Verify the selected workspace, its Tables pane, diagnostic destination, and your access. The table may not be available in that workspace or may differ from the older example.
- Table exists but is empty: Check the query time range and whether diagnostics were enabled for that workspace. Allow time for ingestion; data from before configuration will not be created retroactively.
- Only one join category appears: The other category may genuinely be absent from the ingested data, may use a different label, or may fall outside the selected time range. Review all values with the enumeration query before concluding it is absent from the estate.
- Counts look too high: Check whether you are counting repeated records. Compare
Rowswith distinct devices using a verified identifier, then decide whether a latest-record view is appropriate. - Portal and KQL disagree: Compare time ranges and filters, and account for current portal inventory versus delayed or historical workspace records, retention, and deduplication. Treat the mismatch as a reason to investigate the data path and definitions, not as proof that either view is wrong.
- Join type is blank or unfamiliar: Inspect the raw values and schema. Preserve unknown categories for follow-up rather than forcing them into one of the two expected groups.
- Records are older than expected: Check the selected time range, ingestion, device reporting, and workspace retention. A timestamp in this table should not be treated as an Intune check-in timestamp unless the schema explicitly establishes that meaning.
Turning the query into ongoing reporting
Once the workspace’s schema, values, and counting method are understood, the comparison query can serve as the basis for a Log Analytics workbook, export, or other reporting pipeline. For migration tracking, use consistent time windows and a consistent definition of “device,” and preserve unexpected values so changes in the data are visible. For scheduled inventory integration or reconciliation across Intune and Entra, Microsoft Graph may be a better fit than an interactive KQL query; account for API permissions, pagination, and throttling in an implementation.
Intune Device Query is a separate capability from querying the tenant-wide IntuneDevices table. HTMD describes it as a KQL-like way to query an individual device, with availability dependent on licensing that includes Intune Advanced Analytics; it is intended for device investigation, not this Log Analytics fleet aggregation. See HTMD’s overview of KQL and Intune Device Query.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

