{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
        "slug": "dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/"
        },
        "title": "Retrieve Intune device diagnostics before the collection expires",
        "summary": "How will the support team preserve an available Intune diagnostic collection in time?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:31+00:00",
        "modified_at": "2026-09-10T01:23:48+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 231,
        "potentially_affected": "This brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.",
        "dse_recommendation": "Give each collection a case owner, target device identity, and download deadline.",
        "primary_source": {
            "name": "Device Action: Collect Diagnostics - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune retains a device diagnostic collection for 28 days and permits up to ten stored collections per device. The device must be online and able to reach the service; failure to receive the action within 24 hours can cause collection failure. Regional upload endpoints must be reachable. Diagnostics can include identifiable user or device names. <a href=\"https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.</p>\n<h2>DSE recommendation</h2>\n<p>Give each collection a case owner, target device identity, and download deadline. Ask that owner to retrieve the package promptly rather than treating the portal as a permanent case archive. Store the download under the organization’s approved access and retention controls. Keep the raw package out of broadly visible tickets; describe the fault and collection status without copying personal information unnecessarily.</p>\n<h2>Verification</h2>\n<p>Check the action status and obtain the completed package through the device diagnostics view. Confirm that the archive opens and contains evidence relevant to the reported failure and device. For a failed collection, establish whether the device received the action and could reach the documented regional destination before repeating it. Record the collection and retrieval times so an investigator can distinguish missing evidence from a system that was actually examined.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Device Action: Collect Diagnostics</a>.</p>",
        "content_text": "Source facts\nIntune retains a device diagnostic collection for 28 days and permits up to ten stored collections per device. The device must be online and able to reach the service; failure to receive the action within 24 hours can cause collection failure. Regional upload endpoints must be reachable. Diagnostics can include identifiable user or device names. Microsoft Learn.\nApplicability\nThis brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.\nDSE recommendation\nGive each collection a case owner, target device identity, and download deadline. Ask that owner to retrieve the package promptly rather than treating the portal as a permanent case archive. Store the download under the organization’s approved access and retention controls. Keep the raw package out of broadly visible tickets; describe the fault and collection status without copying personal information unnecessarily.\nVerification\nCheck the action status and obtain the completed package through the device diagnostics view. Confirm that the archive opens and contains evidence relevant to the reported failure and device. For a failed collection, establish whether the device received the action and could reach the documented regional destination before repeating it. Record the collection and retrieval times so an investigator can distinguish missing evidence from a system that was actually examined.\nOfficial references\nMicrosoft Learn: Device Action: Collect Diagnostics.",
        "content_markdown": "## Source facts\n\nIntune retains a device diagnostic collection for 28 days and permits up to ten stored collections per device. The device must be online and able to reach the service; failure to receive the action within 24 hours can cause collection failure. Regional upload endpoints must be reachable. Diagnostics can include identifiable user or device names. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics).\n\n## Applicability\n\nThis brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.\n\n## DSE recommendation\n\nGive each collection a case owner, target device identity, and download deadline. Ask that owner to retrieve the package promptly rather than treating the portal as a permanent case archive. Store the download under the organization’s approved access and retention controls. Keep the raw package out of broadly visible tickets; describe the fault and collection status without copying personal information unnecessarily.\n\n## Verification\n\nCheck the action status and obtain the completed package through the device diagnostics view. Confirm that the archive opens and contains evidence relevant to the reported failure and device. For a failed collection, establish whether the device received the action and could reach the documented regional destination before repeating it. Record the collection and retrieval times so an investigator can distinguish missing evidence from a system that was actually examined.\n\n## Official references\n\n[Microsoft Learn: Device Action: Collect Diagnostics](https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Retrieve Intune device diagnostics before the collection expires",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/",
                "headline": "Retrieve Intune device diagnostics before the collection expires",
                "description": "How will the support team preserve an available Intune diagnostic collection in time?",
                "abstract": "How will the support team preserve an available Intune diagnostic collection in time?",
                "articleBody": "Source facts\nIntune retains a device diagnostic collection for 28 days and permits up to ten stored collections per device. The device must be online and able to reach the service; failure to receive the action within 24 hours can cause collection failure. Regional upload endpoints must be reachable. Diagnostics can include identifiable user or device names. Microsoft Learn.\nApplicability\nThis brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.\nDSE recommendation\nGive each collection a case owner, target device identity, and download deadline. Ask that owner to retrieve the package promptly rather than treating the portal as a permanent case archive. Store the download under the organization’s approved access and retention controls. Keep the raw package out of broadly visible tickets; describe the fault and collection status without copying personal information unnecessarily.\nVerification\nCheck the action status and obtain the completed package through the device diagnostics view. Confirm that the archive opens and contains evidence relevant to the reported failure and device. For a failed collection, establish whether the device received the action and could reach the documented regional destination before repeating it. Record the collection and retrieval times so an investigator can distinguish missing evidence from a system that was actually examined.\nOfficial references\nMicrosoft Learn: Device Action: Collect Diagnostics.",
                "datePublished": "2026-09-10T00:27:31+00:00",
                "dateModified": "2026-09-10T01:23:48+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Retrieve Intune device diagnostics before the collection expires"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 231,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Device Action: Collect Diagnostics - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics"
                }
            }
        ]
    }
}