# Treat a live Intune device query as evidence with a trust boundary

> What limits should accompany security conclusions drawn from a live device query?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-148-treat-a-live-intune-device-query-as-evidence-with-a-trust-boundary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:28+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What limits should accompany security conclusions drawn from a live device query?

## Potentially affected

Confirm the corporate-owned Intune device, supported join state, query permission, and required connectivity. Identify the precise property needed for the investigation before querying broader device data.

## DSE recommendation

State what the returned value can support and what needs independent corroboration.

## Article

## Source facts

Single-device query requests Windows state in real time and depends on Windows Push Notification Services. Microsoft warns that a local administrator may alter client information returned by the query. For a device with TPM 2.0, the query returns activated and enabled as true. Oversized results are truncated with an error indicating omitted rows. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-query).

## Applicability

Confirm the corporate-owned Intune device, supported join state, query permission, and required connectivity. Identify the precise property needed for the investigation before querying broader device data.

## DSE recommendation

State what the returned value can support and what needs independent corroboration. Do not present client-reported properties as tamper-proof certification. For a high-impact security decision, ask the control owner to define an additional trusted observation. Keep investigation separate from any remote action available in the query interface; obtaining a result should not itself authorize a change.

## Verification

Compare a narrowly scoped query with an approved observation of the target device. Check for errors or omitted rows before claiming the result is complete. For TPM interpretation, preserve the documented return-value limitation in the case notes rather than interpreting true as a fresh functional test. Retain the query, device identifier, time, and corroborating evidence. If communication fails, record that as a collection failure rather than assuming the requested property is absent.

## Official references

[Microsoft Learn: Device Query](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-query).

## Primary reference

- Name: Device Query - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/advanced-analytics/device-query
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat a live Intune device query as evidence with a trust boundary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-148-treat-a-live-intune-device-query-as-evidence-with-a-trust-boundary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
