Ich freue mich sehr, mein neues Tool, den GPT Intune Device Troubleshooter, zu veröffentlichen. Wäre es nicht großartig, wenn du einen Assistenten hättest, dem du erklären könntest, was du in Intune tun möchtest, und er die Arbeit für dich erledigt? Dieser Traum wird nun mit dem GPT Intune Device Troubleshooter Wirklichkeit.

Inhaltsverzeichnis
Inhalt
- Inhalt
- Was ist der GPT Intune Device Troubleshooter
- Was sind die Voraussetzungen
- Wie funktioniert es
- Zugang zum Open AI Service erhalten
- Wie steht es um den Datenschutz bei Nutzung des Azure Open AI Service
- Wie man den GPT Intune Device Troubleshooter bereitstellt
- Welche Funktionen gibt es aktuell und welche Beispielanfragen
- Wie man die App-Registrierung erstellt
- Schritte nach der Einrichtung
- Wie man die Webseite öffnet
- Wie das Tool funktioniert
- Wie du beitragen kannst?
- Wie sieht die Roadmap aus?
Was ist der GPT Intune Device Troubleshooter
Der GPT Intune Device Troubleshooter ist ein leistungsstarkes Tool, das Intune-Admins den Arbeitsalltag erleichtert. Es beantwortet deine Freitextfragen basierend auf deiner Umgebung und nutzt dafür die Graph API. Du kannst Fragen stellen wie „Kannst du den Status des Geräts XXXX prüfen” oder „Kannst du mir eine Geräteliste mit allen Android-Geräten als CSV geben” und erhältst die passende Antwort auf deine Frage.
Was sind die Voraussetzungen
- GPT-fähiges Abonnement
- App-Registrierung mit delegierten Berechtigungen für (DeviceManagementConfiguration.Read.All, DeviceManagementManagedDevices.Read.All, DeviceManagementApps.Read.All, User.Read)

Wie funktioniert es

- Du kannst die Infrastruktur mit einem Klick von GitHub nach Azure bereitstellen
- Der Code wird in den App Service geladen
- Der Benutzer öffnet die Streamlit-Webseite
- Der Benutzer authentifiziert sich über eine App-Registrierung mit delegierten Berechtigungen für Graph
- Dieses Token wird verwendet, um Daten von Graph abzurufen und in einen Prompt einzufügen
- Dieser Prompt mit der Frage und den angereicherten Informationen wird an den Open AI Service gesendet
- Die Antwort wird auf der Streamlit-Webseite angezeigt

Zugang zum Open AI Service erhalten
Fülle das folgende Antragsformular aus, um dein Abonnement für die Bereitstellung von Open AI Services freizuschalten.
Wie steht es um den Datenschutz bei Nutzung des Azure Open AI Service
Weitere Informationen zum Datenschutz findest du in diesem MS-Dokument.
Wie man den GPT Intune Device Troubleshooter bereitstellt
Du musst nicht viel tun. Die ganze Magie steckt hinter diesem Button.
Du kannst die Infrastruktur und den Code aber auch manuell über mein GitHub-Repository bereitstellen.

- Wähle das Abonnement und die Ressourcengruppe aus
- Wähle die Region und die Website-SKU aus
- Gib einen Namen für die Site und das Open AI Service-Konto ein
Welche Funktionen gibt es aktuell und welche Beispielanfragen
Aktuell werden die folgenden Funktionen unterstützt:
- Geräteliste abrufen
- Gerätestatus abrufen
- Einzelnes Gerät abrufen
- Intune How-To
- Konfigurationsprofile
- App-Liste
- Compliance-Richtlinien
- Gruppenmitgliedschaft von Geräten
- Graph Call
Beispiele sind:
- Kannst du mir eine Geräteliste mit allen Android-Geräten als CSV geben
- Kannst du den Status des Geräts XXXXX prüfen
- Kannst du den Status des Geräts XXXX prüfen und die Objekte auflisten, die einen Konflikt haben oder Fehler aufweisen
- Kannst du mir eine Liste aller Anwendungen geben
- Kannst du mir eine Liste als CSV mit allen Apps zeigen, die nach dem 01.01.2022 erstellt wurden
- In welchen Gruppen ist XXXX? Kannst du mir den Anzeigenamen und die IDs geben
Wie man die App-Registrierung erstellt
- Öffne das Entra-Portal
- Wähle App-Registrierung

- Klicke auf + Neue Registrierung
- Gib einen Namen für die App-Registrierung ein
- Wähle Single-Page Application (SPA) als Umleitungstyp
- Füge
https://WEBPAGENAME.azurewebsites.net/login/callbackals Umleitungs-URI hinzu

- Kopiere die App-ID

- Gehe zu API-Berechtigungen und klicke auf + Berechtigung hinzufügen

- Wähle Graph

- Wähle Delegierte Berechtigungen

- Füge die folgenden Berechtigungen hinzu (DeviceManagementConfiguration.Read.All, DeviceManagementManagedDevices.Read.All, DeviceManagementApps.Read.All, Group.Read.All, User.Read, Device.Read.All)
- Klicke auf Administratorzustimmung für XXX erteilen

Schritte nach der Einrichtung
Füge die App-ID und das Secret des Open AI Service zu den Variablen in der App Service-Konfiguration hinzu.
- Öffne den Open AI Service

- Gehe zu Keys and Endpoint

- Öffne den App Service

- Navigiere zu Configurations
- Trage den Azure Open AI Key und die App-ID in die Variablen ein

Wie man die Webseite öffnet
- Gehe zum App Service und wähle Browse

Wie das Tool funktioniert
- Klicke auf Login, um ein Token zur Authentifizierung an Graph zu erhalten

- Gib deine Frage in das Chatfeld ein

Wie du beitragen kannst?
Wenn du Ideen für Verbesserungen oder fehlende Funktionen sowie Bugs hast, kontaktiere mich über meinen Blog, die sozialen Medien oder öffne ein Issue im Repository mit einer Beschreibung deiner Idee. Du kannst auch einen Merge Request erstellen. Ich freue mich über jeden Beitrag und jedes Feedback.
Wie sieht die Roadmap aus?
Bitte gib mir Feedback. Basierend auf deinem Feedback werde ich die Funktionen aufnehmen und priorisieren, die ich hinzufügen werde.



Hi Jannik,
Great work and thanks for the demo at the Endpoint Management Summit. We tried it out in our demo tenant.
When i ask for a device list it works ok, but if i the same question again it says “None”.
How can we troubleshoot this?
Hi Jannik,
What is the scope of questions and how can we troubleshoot if questions asked are answered with “none”?
I got this feedback from several person. I am in the investigation
Thanks for theis, this could be game changing. After deploying, we get normal chatgpt responses, but it simply answers ‘none’ to any questions about our tenant. anything jump out that we might have missed?
I got this feedback from several person. I am in the investigation
Looks great! Question would this work with Azure Openai ?
It is build based on azure open ai 😀
Hi Jannik, I’ve implemented your solution but all the queries you mentioned come back as “None”. Do you know if something happened that is causing this issue? Thanks
I got this feedback from several person. I am in the investigation
Hi Jannik, I just deployed the template in my tenant for testing and configured the settings like you described in the blog post. Unfortunately after I hit login and choose the user nothing happens. I’m not logged and therefore can’t use the site. Tried it already with different user accounts of the tenant. Is this problem already known?
@christian, what error message do you get? I logged in successfully.
@Jannik, I am waiting on your reply to the “none” reply issue. Everything I ask in the chat, I am also getting the answer “none” from the bot. I have to say that I gave the app registration more read rights than given in this article, because I want him to read and tell me a lot more. Example, we have multiple countries and all in Intune, so I want to ask in the chat to sent me a list of all users in a specific security group and list all devices per users that are a member of that group. is that even possible for this ai bot?
@christian, what error message do you get? I logged in successfully.
@Jannik, I am waiting on your reply to the “none” reply issue. Everything I ask in the chat, I am also getting the answer “none” from the bot. I have to say that I gave the app registration more read rights than given in this article, because I want him to read and tell me a lot more. Example, we have multiple countries and all in Intune, so I want to ask in the chat to sent me a list of all users in a specific security group and list all devices per users that are a member of that group. is that even possible for this ai bot?
Hi Jannik, with version 1.27.0 of Streamlit (released towards the end of September) your script no longer seems to work. Here the error:
TypeError: expected string or bytes-like object
Tracebacks:
File “/tmp/8dbd0b0d9280f02/antenv/lib/python3.10/site-packages/streamlit/runtime/scriptrunner/script_runner.py”, line 541, in run
scripts
exec(code, module.dict)File “/tmp/8dbd0b0d9280f02/website/app.py”, line 161, in
response = util.get_category(category_list, prompt)File “/tmp/8dbd0b0d9280f02/website/modules/utility.py”, line 169, in get_category
category_match = re.search(r’Category:\s(.?)\s*(?=Devicename|$)’, response, re.I | re.S)File “/opt/python/3.10.12 /lib/python3.10/re.py”, line 200, in search
return _compile(pattern, flags).search(string)
@mrv, I was able to log in successfully after deleting the Azure RG and redeploying the whole template to a different subscription. I don’t know what exactly the problem was but it is fixed now.
Hi There I just got the okay to have this deployed to Azure and I’m a newbie to this, but when I set the deploy with thefollowing as I’m in Canada east side I get the errors below.
Basics
Subscription
Microsoft Azure Sponsorship
Resource group
IntuneAI
Region
Canada East
Sites_name
IntuneCLC
Accounts_name
IntuneOpenCLC
Website_sku
F1
The specified SKU ‘Standard’ for model ‘gpt-35-turbo 0301’ is not supported in this region ‘canadaeast’. (Code: InvalidResourceProperties)
Validation failed for a resource. Check ‘Error.Details[0]’ for more information. (Code: ValidationForResourceFailed)
This subscription has reached the limit of 1 Free Linux app service plan(s) it can create in this region. Please choose a different sku or region. (Code: FreeLinuxAtRegionalCapacityForSubscription)
Can you tell me what I’m doing wrong? I’ve tried different locations and SKU but still fails
The problem is that the region you selected dont support the gpt service. Can you switch to an other one. Here you can find the supported locations:
https://learn.microsoft.com/en-us/azure/ai-services/openai/concepts/models
I have followed this Blog and Deans Video too – all configs are up and running, i can logon OK but when asking to show me a list of windows devices in my tenant I get NONE. Same for ios devices etc… infact every response i get is NONE.
Hi Jannik, any more news on the issue of NONE responses?
Hey sorry for this late response. I got this error reported from many testers. Currently I have limited time to investigate into this issue and I can’t reproduce this. Will try to work on this in the coming days.