# Retrieve Intune device diagnostics before the collection expires

> How will the support team preserve an available Intune diagnostic collection in time?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:31+00:00
- Modified: 2026-09-10T01:23:48+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

How will the support team preserve an available Intune diagnostic collection in time?

## Potentially affected

This brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.

## DSE recommendation

Give each collection a case owner, target device identity, and download deadline.

## Article

## Source facts

Intune retains a device diagnostic collection for 28 days and permits up to ten stored collections per device. The device must be online and able to reach the service; failure to receive the action within 24 hours can cause collection failure. Regional upload endpoints must be reachable. Diagnostics can include identifiable user or device names. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics).

## Applicability

This brief concerns the Windows corporate-owned device collection workflow. Review its platform and permission requirements separately from mobile application diagnostics, and identify the tenant’s region before investigating upload connectivity.

## DSE recommendation

Give each collection a case owner, target device identity, and download deadline. Ask that owner to retrieve the package promptly rather than treating the portal as a permanent case archive. Store the download under the organization’s approved access and retention controls. Keep the raw package out of broadly visible tickets; describe the fault and collection status without copying personal information unnecessarily.

## Verification

Check the action status and obtain the completed package through the device diagnostics view. Confirm that the archive opens and contains evidence relevant to the reported failure and device. For a failed collection, establish whether the device received the action and could reach the documented regional destination before repeating it. Record the collection and retrieval times so an investigator can distinguish missing evidence from a system that was actually examined.

## Official references

[Microsoft Learn: Device Action: Collect Diagnostics](https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics).

## Primary reference

- Name: Device Action: Collect Diagnostics - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-management/actions/collect-diagnostics
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Retrieve Intune device diagnostics before the collection expires,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-265-retrieve-intune-device-diagnostics-before-the-collection-expires/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
