Skip to content

Commit 6192fc2

Browse files
committed
Autopilot diags 2
1 parent 72f0708 commit 6192fc2

4 files changed

Lines changed: 87 additions & 75 deletions

File tree

memdocs/intune/remote-actions/collect-diagnostics.md

Lines changed: 87 additions & 75 deletions
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,9 @@ ms.collection: M365-identity-device-management
3131

3232
# Collect diagnostics from a Windows device
3333

34-
The **Collect diagnostics** remote action lets you collect and download Windows device logs without interrupting the user. Only non-user locations and file types can be accessed, so no personal information is collected.
34+
The **Collect diagnostics** remote action lets you collect and download Windows device logs without interrupting the user. Only non-user locations and file types are accessed.
3535

36-
Autopilot diagnostics can also be captured automatically when devices experience a failure during the Autopilot process. When logs are finished processing on a failed device, they will be automatically captured and uploaded to Intune. Autopilot diagnostics and logs may include user identifiable information such as user name or device name.
36+
The **Collect diagnostics** remote action can also be configured to automatically collect and upload Windows devices logs upon an Autopilot failure on a device. When an Autopilot failure occurs, logs will be processed on the failed device and then automatically captured and uploaded to Intune.
3737

3838
The diagnostic collection is stored for 28 days and then deleted. Each device can have up to 10 collections stored at one time.
3939

@@ -55,110 +55,122 @@ The *Collect diagnostics* remote action is supported for:
5555

5656
To use the *Collect diagnostics* action:
5757

58-
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Devices** > **Windows** > select a supported device.
59-
2. On the device’s **Overview** page, select **** > **Collect diagnostics** > **Yes**. A pending notification appears on the device’s **Overview** page.
60-
3. To see the status of the action, select **Device diagnostics monitor**.
61-
4. After the action completes, select **Download** in the row for the action > **Yes**.
62-
5. The data zip file is added to your download tray and you can save it to your computer.
58+
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431)
59+
2. Navigate to **Devices** > **Windows** > select a supported device.
60+
3. On the device’s **Overview** page, select **** > **Collect diagnostics** > **Yes**. A pending notification appears on the device’s **Overview** page.
61+
4. To see the status of the action, select **Device diagnostics monitor**.
62+
5. After the action completes, select **Download** in the row for the action > **Yes**.
63+
6. The data zip file is added to your download tray and you can save it to your computer.
64+
65+
## Diagnostics collection on Autopilot failure
66+
67+
For Autopilot diagnostics collection, no additional action is required. Autopilot diagnostics will be automatically captured when devices experience a failure as long as the Autopilot automatic capture diagnostic feature is enabled.
6368

64-
> [!NOTE]
65-
> For Autopilot diagnostics collection, no additional action is required. Autopilot diagnostics will be automatically captured when devices experience a failure as long as the Autopilot automatic capture diagnostic feature is enabled.
69+
To view the diagnostics collected after an Autopilot failure:
70+
71+
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431)
72+
2. Navigate to **Devices** > **Monitor** > **Autopilot deployments (preview)**.
73+
3. In the middle pane, select a device.
74+
4. On the right hand **Properties** pane, under **Device Diagnostics**, select **Download**.
75+
5. The data zip file is added to your download tray and you can save it to your computer.
6676

6777
## Data collected
6878

69-
No personal information is collected. If you've installed [KB5011543](https://support.microsoft.com/topic/march-22-2022-kb5011543-os-builds-19042-1620-19043-1620-and-19044-1620-preview-4fe2d1c0-720f-47fe-9523-75339bc107a1) on Windows 10 or [KB5011563](https://support.microsoft.com/topic/march-28-2022-kb5011563-os-build-22000-593-preview-40df54c9-b5a9-42e5-ae1c-9a33ff91ca91) on Windows 11, the format of the zip file will be simpler, including a flattened structure where the logs collected are named to match the data collected, and when multiple files are collected a folder is created.
79+
While there is no intent to collect personal data, some identifiable information such as user names or device name might be collected when they are contained in collected logs or data from other locations.
80+
81+
If you've installed [KB5011543](https://support.microsoft.com/topic/march-22-2022-kb5011543-os-builds-19042-1620-19043-1620-and-19044-1620-preview-4fe2d1c0-720f-47fe-9523-75339bc107a1) on Windows 10 or [KB5011563](https://support.microsoft.com/topic/march-28-2022-kb5011563-os-build-22000-593-preview-40df54c9-b5a9-42e5-ae1c-9a33ff91ca91) on Windows 11, the format of the zip file will be simpler, including a flattened structure where the logs collected are named to match the data collected, and when multiple files are collected a folder is created.
7082

7183
This list below is the same order as the diagnostic zip. Each collection contains the following data:
7284

7385
Registry Keys:
7486

75-
1. HKLM\SOFTWARE\Microsoft\CloudManagedUpdate
76-
1. HKLM\SOFTWARE\Microsoft\IntuneManagementExtension
77-
1. HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
78-
1. HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection
79-
1. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI
80-
1. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
81-
1. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
82-
1. HKLM\SOFTWARE\Policies
83-
1. HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL
84-
1. HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
85-
1. HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
86-
1. HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
87-
1. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Mdm
87+
- HKLM\SOFTWARE\Microsoft\CloudManagedUpdate
88+
- HKLM\SOFTWARE\Microsoft\IntuneManagementExtension
89+
- HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
90+
- HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection
91+
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI
92+
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
93+
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
94+
- HKLM\SOFTWARE\Policies
95+
- HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL
96+
- HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
97+
- HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
98+
- HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
99+
- HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Mdm
88100

89101
Commands:
90102

91-
1. %programfiles%\windows defender\mpcmdrun.exe -GetFiles
92-
1. %windir%\system32\certutil.exe -store
93-
1. %windir%\system32\certutil.exe -store -user my
94-
1. %windir%\system32\Dsregcmd.exe /status
95-
1. %windir%\system32\ipconfig.exe /all
96-
1. %windir%\system32\mdmdiagnosticstool.exe
97-
1. %windir%\system32\msinfo32.exe /report %temp%\MDMDiagnostics\msinfo32.log
98-
1. %windir%\system32\netsh.exe advfirewall show allprofiles
99-
1. %windir%\system32\netsh.exe advfirewall show global
100-
1. %windir%\system32\netsh.exe lan show profiles
101-
1. %windir%\system32\netsh.exe winhttp show proxy
102-
1. %windir%\system32\netsh.exe wlan show profiles
103-
1. %windir%\system32\netsh.exe wlan show wlanreport
104-
1. %windir%\system32\ping.exe -n 50 localhost
105-
1. %windir%\system32\powercfg.exe /batteryreport /output %temp%\MDMDiagnostics\battery-report.html
106-
1. %windir%\system32\powercfg.exe /energy /output %temp%\MDMDiagnostics\energy-report.html
103+
- %programfiles%\windows defender\mpcmdrun.exe -GetFiles
104+
- %windir%\system32\certutil.exe -store
105+
- %windir%\system32\certutil.exe -store -user my
106+
- %windir%\system32\Dsregcmd.exe /status
107+
- %windir%\system32\ipconfig.exe /all
108+
- %windir%\system32\mdmdiagnosticstool.exe
109+
- %windir%\system32\msinfo32.exe /report %temp%\MDMDiagnostics\msinfo32.log
110+
- %windir%\system32\netsh.exe advfirewall show allprofiles
111+
- %windir%\system32\netsh.exe advfirewall show global
112+
- %windir%\system32\netsh.exe lan show profiles
113+
- %windir%\system32\netsh.exe winhttp show proxy
114+
- %windir%\system32\netsh.exe wlan show profiles
115+
- %windir%\system32\netsh.exe wlan show wlanreport
116+
- %windir%\system32\ping.exe -n 50 localhost
117+
- %windir%\system32\powercfg.exe /batteryreport /output %temp%\MDMDiagnostics\battery-report.html
118+
- %windir%\system32\powercfg.exe /energy /output %temp%\MDMDiagnostics\energy-report.html
107119

108120
Event Viewers:
109121

110-
1. Application
111-
1. Microsoft-Windows-AppLocker/EXE and DLL
112-
1. Microsoft-Windows-AppLocker/MSI and Script
113-
1. Microsoft-Windows-AppLocker/Packaged app-Deployment
114-
1. Microsoft-Windows-AppLocker/Packaged app-Execution
115-
1. Microsoft-Windows-AppxPackaging/Operational
116-
1. Microsoft-Windows-Bitlocker/Bitlocker Management
117-
1. Microsoft-Windows-HelloForBusiness/Operational
118-
1. Microsoft-Windows-SENSE/Operational
119-
1. Microsoft-Windows-SenseIR/Operational
120-
1. Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
121-
1. Microsoft-Windows-WinRM/Operational
122-
1. Microsoft-Windows-WMI-Activity/Operational
123-
1. Setup
124-
1. System
122+
- Application
123+
- Microsoft-Windows-AppLocker/EXE and DLL
124+
- Microsoft-Windows-AppLocker/MSI and Script
125+
- Microsoft-Windows-AppLocker/Packaged app-Deployment
126+
- Microsoft-Windows-AppLocker/Packaged app-Execution
127+
- Microsoft-Windows-AppxPackaging/Operational
128+
- Microsoft-Windows-Bitlocker/Bitlocker Management
129+
- Microsoft-Windows-HelloForBusiness/Operational
130+
- Microsoft-Windows-SENSE/Operational
131+
- Microsoft-Windows-SenseIR/Operational
132+
- Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
133+
- Microsoft-Windows-WinRM/Operational
134+
- Microsoft-Windows-WMI-Activity/Operational
135+
- Setup
136+
- System
125137

126138
Files:
127139

128-
1. %ProgramData%\Microsoft\DiagnosticLogCSP\Collectors\*.etl
129-
1. %ProgramData%\Microsoft\IntuneManagementExtension\Logs\*.*
130-
1. %ProgramData%\Microsoft\Windows Defender\Support\MpSupportFiles.cab
131-
1. %ProgramData%\Microsoft\Windows\WlanReport\wlan-report-latest.html
132-
1. %ProgramData Microsoft Update Health Tools\Logs\*.etl
133-
1. %temp%\MDMDiagnostics\battery-report.html
134-
1. %temp%\MDMDiagnostics\energy-report.html
135-
1. %temp%\MDMDiagnostics\mdmlogs-<Date/Time>.cab
136-
1. %temp%\MDMDiagnostics\msinfo32.log
137-
1. %windir%\ccm\logs\*.log
138-
1. %windir%\ccmsetup\logs\*.log
139-
1. %windir%\logs\CBS\cbs.log
140-
1. %windir%\logs\measuredboot\*.*
141-
1. %windir%\Logs\WindowsUpdate\*.etl
142-
1. %windir%\temp\%computername%*.log
143-
1. %windir%\temp\officeclicktorun*.log
140+
- %ProgramData%\Microsoft\DiagnosticLogCSP\Collectors\*.etl
141+
- %ProgramData%\Microsoft\IntuneManagementExtension\Logs\*.*
142+
- %ProgramData%\Microsoft\Windows Defender\Support\MpSupportFiles.cab
143+
- %ProgramData%\Microsoft\Windows\WlanReport\wlan-report-latest.html
144+
- %ProgramData Microsoft Update Health Tools\Logs\*.etl
145+
- %temp%\MDMDiagnostics\battery-report.html
146+
- %temp%\MDMDiagnostics\energy-report.html
147+
- %temp%\MDMDiagnostics\mdmlogs-<Date/Time>.cab
148+
- %temp%\MDMDiagnostics\msinfo32.log
149+
- %windir%\ccm\logs\*.log
150+
- %windir%\ccmsetup\logs\*.log
151+
- %windir%\logs\CBS\cbs.log
152+
- %windir%\logs\measuredboot\*.*
153+
- %windir%\Logs\WindowsUpdate\*.etl
154+
- %windir%\temp\%computername%*.log
155+
- %windir%\temp\officeclicktorun*.log
144156

145157
## Disable device diagnostics
146158

147-
You can disable the **Collect diagnostics** remote action for all devices by following these steps:
159+
The the **Collect diagnostics** remote action is enabled by default. You can disable the **Collect diagnostics** remote action for all devices by following these steps:
148160

149161
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Tenant administration** > **Device diagnostics**.
150162
2. Change the control under **Device diagnostics are available for corporate-managed devices running Windows 10, version 1909 and later, or Windows 11.** to **Disabled**.
151163

152-
:::image type="content" source="./media/collect-diagnostics/disable-device-diagnostics.png" alt-text="Screenshot that shows the Device diagnostics pane with the highlighted control set to Disabled.":::
164+
:::image type="content" source="./media/collect-diagnostics/disable-device-diagnostics.png" alt-text="Screenshot that shows the Device diagnostics pane with the highlighted control for device diagnostics set to Disabled.":::
153165

154-
## Disable Autopilot diagnostics
166+
## Disable Autopilot automatic collection of diagnostics
155167

156-
You can disable Autopilot automatic diagnostic capture by following these steps:
168+
Autopilot automatic diagnostic capture is enabled by default. You can disable Autopilot automatic diagnostic capture by following these steps:
157169

158170
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Tenant administration** > **Device diagnostics**.
159171
2. Change the control under **Automatically capture diagnostics when devices experience a failure during the Autopilot process on Windows 10 version 1909 or later and Windows 11. Diagnostics may include user identifiable information such as user or device name (preview).** to **Disabled**.
160172

161-
:::image type="content" source="./media/collect-diagnostics/disable-autopilot-diagnostics.png" alt-text="Screenshot that shows the Device diagnostics pane with the highlighted control set to Disabled.":::
173+
:::image type="content" source="./media/collect-diagnostics/disable-autopilot-diagnostics.png" alt-text="Screenshot that shows the Device diagnostics pane with the highlighted control for Autopilot automatic diagnostics collection set to Disabled.":::
162174

163175
## Known issues with device diagnostics
164176

-77 Bytes
Loading
43.6 KB
Loading
64.5 KB
Loading

0 commit comments

Comments
 (0)