For the complete documentation index, see llms.txt. This page is also available as Markdown.

Report Devices Without Primary User Scheduled

Reports all managed devices in Intune that do not have a primary user assigned.

This is a scheduled runbook. It is designed to run on a recurring schedule rather than being triggered for a single object. See Scheduling for details on how to configure runbook schedules.

Description

This script retrieves all managed devices from Intune, and filters out those without a primary user (userId). The output is a formatted table showing Object ID, Device ID, Display Name, Operating System, and Last Sync Date/Time for each device without a primary user. The report can be limited to specific platforms (Windows, macOS, iOS/iPadOS, Android, Other) via boolean parameters. By default, all platforms are included.

Optionally, the report can be sent via email with CSV and/or Excel (xlsx) attachments containing detailed device information. The report files can also be uploaded to an Azure Storage Account, returning time-limited download links. The ReportFileFormat parameter controls which file formats are generated and delivered (CSV only, CSV & XLSX, or XLSX only). When the CSV attachment exceeds the email size limit and "CSV & XLSX" is selected, the email falls back to the Excel workbook alone.

Setup regarding email sending

Sending an email report is optional and only happens when a recipient (EmailTo) is provided. The sender address is taken from the RJReport.EmailSender tenant setting.

This runbook sends emails using the Microsoft Graph API. To send emails via Graph API, you need to configure an existing email address in the runbook customization.

See the RealmJoin Report Settings documentation for details.

Location

Organization → Devices → Report Devices Without Primary User (Scheduled)

Full Runbook name

rjgit-org_devices_report-devices-without-primary-user_scheduled

Details

Property
Value

Version

1.7.0

Required modules

RealmJoin.RunbookHelper (>= 0.8.7) Microsoft.Graph.Authentication (>= 2.39.0) Az.Accounts (>= 5.3.4)

Schedulable

yes

Permissions

Application permissions

  • Type: Microsoft Graph

    • DeviceManagementManagedDevices.Read.All

    • Mail.Send

Parameters

IncludeWindows

Include Windows devices in the report. Enabled by default.

Property
Value

Required

false

Default Value

True

Type

Boolean

Portal display name

Include Windows Devices

IncludeMacOS

Include macOS devices in the report. Enabled by default.

Property
Value

Required

false

Default Value

True

Type

Boolean

Portal display name

Include macOS Devices

IncludeIOS

Include iOS and iPadOS devices in the report. Enabled by default.

Property
Value

Required

false

Default Value

True

Type

Boolean

Portal display name

Include iOS/iPadOS Devices

IncludeAndroid

Include Android devices in the report. Enabled by default.

Property
Value

Required

false

Default Value

True

Type

Boolean

Portal display name

Include Android Devices

IncludeOther

Include devices with any other operating system (e.g. Linux, ChromeOS) in the report. Enabled by default.

Property
Value

Required

false

Default Value

True

Type

Boolean

Portal display name

Include Other Devices (e.g. Linux, ChromeOS)

ReportFileFormat

Controls which report file formats are generated and delivered: "CSV only", "CSV & XLSX" (default) or "XLSX only".

Property
Value

Required

false

Default Value

CSV & XLSX

Type

String

Portal display name

Report file format

Portal options

Portal option
Value

CSV & XLSX

CSV only

XLSX only

If enabled, the report files are uploaded to an Azure Storage Account and time-limited download links are returned. Disabled by default.

Property
Value

Required

false

Default Value

False

Type

Boolean

Portal display name

Create a file download link (upload report to storage)?

Portal options

Portal option
Value

Yes - upload report and return a download link

true

No - do not create a download link

false

ContainerName

Storage container name used for the upload. Configured per runbook (not a global RJReport setting).

Property
Value

Required

false

Default Value

devices-without-primary-user

Type

String

Hidden in portal

yes (preset via runbook customization)

ResourceGroupName

Resource group that contains the storage account. Sourced from the RJReport tenant settings.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

StorageAccountName

Storage account name used for the upload. Sourced from the RJReport tenant settings.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

LinkExpiryDays

Number of days until the generated download link expires. Sourced from the RJReport tenant settings.

Property
Value

Required

false

Default Value

6

Type

Int32

Hidden in portal

yes (preset via runbook customization)

EmailFrom

The sender email address. This needs to be configured in the runbook customization.

Property
Value

Required

false

Default Value

Type

String

Hidden in portal

yes (preset via runbook customization)

EmailTo

If specified, an email with the report will be sent to the provided address(es). Can be a single address or multiple comma-separated addresses (string). The function sends individual emails to each recipient for privacy reasons.

Property
Value

Required

false

Default Value

Type

String

Portal display name

Recipient Email Address(es)

Last updated

Was this helpful?