Accessing Event Viewer Logs on AAD Remote Computer

Mikkel Lund Knudsen 116 Reputation points
2022-09-07T14:22:54.207+00:00

Hey,

So we got a bunch of supporters asking for how to access Event Viewer Remotely.

Devices are Windows 11 running AAD. (not hybrid).

What do we need to configure in Intune, and which firewall ports are required to be opened?

Microsoft Security Intune Other
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2022-09-08T01:29:01.513+00:00

    @Mikkel Lund Knudsen , Based on my research, Intune has a feature "Windows 10 Device diagnostics" which utilizes the Windows DiagnosticLog CSP, allowing Intune to collect a set of files, like registry, event viewers and commands. For the event viewer log, it contains Application, System, Setup and Applocker related event log. We can see more details in the following link:
    https://learn.microsoft.com/en-us/mem/intune/remote-actions/collect-diagnostics

    On windows 11 device, we can also use this feature. on the device, select "Collect diagnostics" to collect the log. After the status shows complete. Go to "Device diagnostics" and click download button to download the logs.
    238779-image.png
    https://techcommunity.microsoft.com/t5/intune-customer-success/intune-public-preview-windows-10-device-diagnostics/ba-p/2179712

    In addition, for the firewall port, I didn't find the official article mentioned any additional ports required. We can firstly try the above feature. if it is failed to collect due to port issue, we can capture netmon log to see which port is used.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.