Report Devices Without Primary User Scheduled
Reports all managed devices in Intune that do not have a primary user assigned.
This is a scheduled runbook. It is designed to run on a recurring schedule rather than being triggered for a single object. See Scheduling for details on how to configure runbook schedules.
Description
This script retrieves all managed devices from Intune, and filters out those without a primary user (userId). The output is a formatted table showing Object ID, Device ID, Display Name, Operating System, and Last Sync Date/Time for each device without a primary user. The report can be limited to specific platforms (Windows, macOS, iOS/iPadOS, Android, Other) via boolean parameters. By default, all platforms are included.
Optionally, the report can be sent via email with CSV and/or Excel (xlsx) attachments containing detailed device information. The report files can also be uploaded to an Azure Storage Account, returning time-limited download links. The ReportFileFormat parameter controls which file formats are generated and delivered (CSV only, CSV & XLSX, or XLSX only). When the CSV attachment exceeds the email size limit and "CSV & XLSX" is selected, the email falls back to the Excel workbook alone.
Setup regarding email sending
Sending an email report is optional and only happens when a recipient (EmailTo) is provided. The sender address is taken from the RJReport.EmailSender tenant setting.
This runbook sends emails using the Microsoft Graph API. To send emails via Graph API, you need to configure an existing email address in the runbook customization.
See the RealmJoin Report Settings documentation for details.
Location
Organization → Devices → Report Devices Without Primary User (Scheduled)
Full Runbook name
rjgit-org_devices_report-devices-without-primary-user_scheduled
Details
Version
1.7.0
Required modules
RealmJoin.RunbookHelper (>= 0.8.7) Microsoft.Graph.Authentication (>= 2.39.0) Az.Accounts (>= 5.3.4)
Schedulable
yes
Permissions
Application permissions
Type: Microsoft Graph
DeviceManagementManagedDevices.Read.All
Mail.Send
Parameters
IncludeWindows
Include Windows devices in the report. Enabled by default.
Required
false
Default Value
True
Type
Boolean
Portal display name
Include Windows Devices
IncludeMacOS
Include macOS devices in the report. Enabled by default.
Required
false
Default Value
True
Type
Boolean
Portal display name
Include macOS Devices
IncludeIOS
Include iOS and iPadOS devices in the report. Enabled by default.
Required
false
Default Value
True
Type
Boolean
Portal display name
Include iOS/iPadOS Devices
IncludeAndroid
Include Android devices in the report. Enabled by default.
Required
false
Default Value
True
Type
Boolean
Portal display name
Include Android Devices
IncludeOther
Include devices with any other operating system (e.g. Linux, ChromeOS) in the report. Enabled by default.
Required
false
Default Value
True
Type
Boolean
Portal display name
Include Other Devices (e.g. Linux, ChromeOS)
ReportFileFormat
Controls which report file formats are generated and delivered: "CSV only", "CSV & XLSX" (default) or "XLSX only".
Required
false
Default Value
CSV & XLSX
Type
String
Portal display name
Report file format
Portal options
CSV & XLSX
CSV only
XLSX only
CreateDownloadLink
If enabled, the report files are uploaded to an Azure Storage Account and time-limited download links are returned. Disabled by default.
Required
false
Default Value
False
Type
Boolean
Portal display name
Create a file download link (upload report to storage)?
Portal options
Yes - upload report and return a download link
true
No - do not create a download link
false
ContainerName
Storage container name used for the upload. Configured per runbook (not a global RJReport setting).
Required
false
Default Value
devices-without-primary-user
Type
String
Hidden in portal
yes (preset via runbook customization)
ResourceGroupName
Resource group that contains the storage account. Sourced from the RJReport tenant settings.
Required
false
Default Value
Type
String
Hidden in portal
yes (preset via runbook customization)
StorageAccountName
Storage account name used for the upload. Sourced from the RJReport tenant settings.
Required
false
Default Value
Type
String
Hidden in portal
yes (preset via runbook customization)
LinkExpiryDays
Number of days until the generated download link expires. Sourced from the RJReport tenant settings.
Required
false
Default Value
6
Type
Int32
Hidden in portal
yes (preset via runbook customization)
EmailFrom
The sender email address. This needs to be configured in the runbook customization.
Required
false
Default Value
Type
String
Hidden in portal
yes (preset via runbook customization)
EmailTo
If specified, an email with the report will be sent to the provided address(es). Can be a single address or multiple comma-separated addresses (string). The function sends individual emails to each recipient for privacy reasons.
Required
false
Default Value
Type
String
Portal display name
Recipient Email Address(es)
Last updated
Was this helpful?