What Must Be Done First to Use Intune Device Query?

Monitor and optimize health Implement Intune Suite add-on capabilities
Answer Correct answer: C — Onboard the devices to Endpoint analytics, because Intune Device query only reports on devices that are enrolled in Endpoint analytics.

You have a Microsoft 365 E5 subscription. You need to use Device query to gather information about all the devices that are managed by using Microsoft Intune. What should you do first?

  1. Enable Windows license verification.
  2. Onboard the devices to Microsoft Defender for Endpoint.
  3. Onboard the devices to Endpoint analytics. Correct Answer
  4. Create a compliance policy for all the devices.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the prerequisite chain for Intune Device query — Endpoint analytics onboarding (plus Advanced Analytics licensing) — and the trap is reaching for Defender for Endpoint or Endpoint analytics configuration as if they were the enabling step.

Microsoft Intune Device query only returns results for devices that are onboarded to Endpoint analytics, and it additionally relies on the Advanced Analytics licensing included in the Intune Suite or the Advanced Analytics add-on. This page confirms that onboarding devices to Endpoint analytics is the required first step, not Defender for Endpoint onboarding or a compliance policy.

Choosing to onboard the devices to Microsoft Defender for Endpoint, because Device query lives next to advanced hunting and live response in the security tooling family; Defender onboarding feeds Defender-specific telemetry, not the Endpoint analytics dataset that Device query reads.

Community Discussion (3 comments)

Moot2 👍 3 Selected: C
C https://learn.microsoft.com/en-us/mem/analytics/device-query To use Device query on a device, the device must be enrolled in Endpoint Analytics
AleFCI1908 👍 2 Selected: C
correct
JayHall 👍 2
Answer is correct: Onboard the devices to Endpoint analytics. To use Device query in your tenant, you must have a license that includes Microsoft Intune Advanced Analytics. Advanced Analytics features are available with: The Intune Advanced Analytics Add-on Microsoft Intune Suite To use Device query on a device, the device must be enrolled in Endpoint Analytics. https://learn.microsoft.com/en-us/mem/analytics/device-query

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Device query is a Microsoft Intune feature that runs KQL-style queries against the inventory and telemetry data collected by Endpoint analytics, so a device can only be queried once it has been enrolled/onboarded to Endpoint analytics and has begun reporting. Availability also depends on licensing that includes Microsoft Intune Advanced Analytics, delivered through the Intune Advanced Analytics Add-on or the Microsoft Intune Suite — the E5 subscription in the scenario does not by itself satisfy that prerequisite, but the practical "first" step asked about is the onboarding. As Moot2 noted, "To use Device query on a device, the device must be enrolled in Endpoint Analytics", which matches Microsoft's documented requirement. Onboarding to Endpoint analytics therefore delivers the data source that Device query consumes, making option C the enabling action.

Why the Other Options Are Wrong

Enabling Windows license verification (A) is a Defender for Endpoint/Windows licensing check with no bearing on whether Device query can see a device. Onboarding devices to Microsoft Defender for Endpoint (B) populates Defender XDR data — a different dataset, useful for advanced hunting but not the Endpoint analytics reports and Device query schema. Creating a compliance policy for all devices (D) merely sets a state rule and produces compliance status; it neither onboards devices to Endpoint analytics nor creates the telemetry store Device query reads. None of A, B or D removes the actual blocker, which is that the device must be reporting into Endpoint analytics.

Community Comment Notes

The voting on this item is unanimous at C, and the reasoning in the comments is the licensing and onboarding chain rather than guesswork. Moot2 supplied the vendor link to the Device query documentation and quoted its requirement that a device "must be enrolled in Endpoint Analytics". JayHall added a licensing nuance — Advanced Analytics ships with the Intune Advanced Analytics Add-on or Microsoft Intune Suite — which is a useful reminder that in a real tenant you must also confirm the entitlement, not just the onboarding. AleFCI1908 simply confirmed the answer. The consensus lines up with the vendor documentation, so C is safe to rely on for MD-102.

Official Reference

Exam Strategy

Memorise the prerequisite chain for each analytics feature, not just their names: Endpoint analytics onboarding + Advanced Analytics licensing = Device query. When a question asks what to do "first", pick the action that creates the data source the feature reads, not a policy or a security-tool onboarding that merely sits adjacent to it.

Frequently Asked Questions

Do devices really need Endpoint analytics onboarding before Device query works?

Yes. Device query reads the dataset collected by Endpoint analytics, so an unonboarded device has no data to query and will not appear in results.

Isn't onboarding to Defender for Endpoint enough to run Device query?

No. Defender for Endpoint onboarding feeds Defender XDR telemetry for advanced hunting; Device query in Intune depends on Endpoint analytics data and Advanced Analytics licensing.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide