Detect anomalies in your Intune environment with Azure Cognitive Services – Part 3 Bluescreen of death detection

Detect anomalies in your Intune environment with Azure Cognitive Services – Part 3 Bluescreen of death detection

Supported byAdvertisement

Admin By Request
Admin By Request
Patch My PC App Catalog Sponsor
Patch My PC
Recast Software Compliance Efficiency Sponsor
Recast Software

Update 06.09.2026: This is a historical Azure Anomaly Detector tutorial. Microsoft’s retirement notice states that the service retires on 1 October 2026. Do not start a new dependency on this service; review existing workloads and plan a supported replacement.

Welcome to the third part of my series in which I describe ways to get proactive notifications when something in your environment has a problem / error. So that this monitoring does not work with static values, I use Azure Cognitive Services (now Azure AI Services) to detect anomalies via machine learning. In this blog we will take a look at the Endpoint Analytics Startup performance bluescreen detection. The goal is to detect anomalies automatically, so we are notified when an unusual number of devices report a blue screen or problem during detection. You can read more about anomaly detection on Microsoft Learn.

Detect anomalies in your Intune environment with Azure Cognitive Services - Bluescreen of death

How did we get the data to detect anomalies

On the Startup performance > Restart frequency page we get all the information we need. I used the Graph X-Ray tool to find out which graph endpoint gives me this information. Btw. this tool is highly recommended; it makes searching for graph calls very easy. So now let’s take a closer look at the call in graph explorer and adjust it so we can later detect anomalies in this BSOD history.

Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea

Looks like exactly what we need. We have a history here and get the information of the average blue screen of death per device, as well as the percentage of BSODs among the restart reasons.

Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea

Then let’s see how we can build proactive anomaly detection to detect anomalies using Azure Automation, Azure AI Services and PowerShell. If you missed it, you can also check out my other posts on jannikreinhard.com covering the rest of this series.

Deployment of the Azure AI Services anomaly detector

  • Click + Create
  • Select a Subscription and Resource group
  • Select a Region and enter the Name of the Anomaly Detector
  • Select the price tier (For testing Free F0 is sufficient)
  • Click Create

Get Teams WebHook URL

  • Create an MS Teams channel and add the webhook connector
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Copy the WebHook URL

Create an App Registration

  • Search for Microsoft Entra ID
  • Select App registration
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Select +New registration
  • Enter a Name and click Register
  • Click API permissions and +Add a permission
  • Select Microsoft Graph
  • Select Application permissions
  • Search for DeviceManagementManagedDevices.Read.All
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Click Grant admin consent for *** and approve with Yes
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Select Certificates & secrets and click +New client secret
  • Enter a Description and select an Expires time
  • Click Add
  • Copy and save the Value and the Secret ID

Create Automation Account

  • Search for Automation Accounts
  • Click + Create
  • Select a Subscription and a Resource group
  • Enter an account name and select a Region
  • Click Next
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Click Next
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Click Next -> Next -> Create
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea

Create the Runbook

  • Open the Automation Account
  • Navigate to Variables and click + Add a variable
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Add the Secret Value, TenantId, AnomalyKey, WebHookUri and the App ID as Variable
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Select Runbooks
  • Click + Create a runbook
  • Enter a Name
  • Select PowerShell as Runbook type
  • Select 5.1 as Runtime version
  • Click Create
  • Insert the Script from my Github repository
  • Edit the variable $anomalyEndpoint (add here your endpoint from the Azure AI Services resource)
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea

Hint: If you want to change the sensitivity of the anomaly detection you can adjust the attributes:
– maxAnomalyRatio: The maximum anomalies to be detected in terms of the ratio of total data points.
– sensitivity: Specify a lower value to ensure that fewer anomalies are accepted

Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Save and test the script
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Click Publish
Detect anomalies in your Intune environment with Azure Cognitive Services - Part 3 Bluescreen of dea
  • Navigate to Schedules and click + Add a schedule
  • Click Link to schedule and add the created schedule

Conclusion: why it pays to detect anomalies early

With an increased occurrence of Bluescreens of Death, it is important to be informed as early as possible so that you can react directly and identify the root cause, e.g. a faulty driver update, and stop or fix it right away. Because this solution uses machine learning to detect anomalies instead of static thresholds, it adapts to your fleet and keeps false alerts low. I hope this blog helped you build such a monitoring solution to detect anomalies in your Intune environment so you can be notified early and react in time.

Stay healthy, Cheers
Jannik

Newsletter

New posts, straight to your inbox.

Hands-on guides on Intune, AI and Azure.

190+ guides · 5x Microsoft MVP · No spam, unsubscribe anytime · Privacy

Portrait of Jannik Reinhard

About the author

Jannik Reinhard

Head of AI @ Epic Fusion · 5x Microsoft MVP

I help enterprises ship secure AI agents. I am Head of AI at Epic Fusion and a 5x Microsoft MVP for AI Platform and Security. I write about Microsoft Foundry, Intune and Azure and publish the implementation details so your team can build it without me.

Comments are closed.