In this post I will show you how to collect Device Diagnostics logs using Intune Portal. MEM Admin center has the ability to collect the Diagnostics logs remotely from the device.
Collecting the diagnostics logs remotely through portal gives the ability to get the logs remotely without disturbing the user. Good thing is that, diagnostics logs are stored for 28 days and we can collect upto 10 collections of these logs.
Verify Device diagnostics is enabled
Make sure Device diagnostics is turned on. Login to MEM Admin center and navigate to Tenant administration > Diagnostics settings.
Device diagnostics are available for corporate-managed devices running Windows 10, version 1909 and later, or Windows 11 should be Enabled.

Initiate Device Diagnostics on Intune portal
On MEM Admin Center, navigate to Devices and click on specific device. With Overview option selected, click on Collect diagnostics.
Click on Yes to initiate collecting the diagnostics logs.

You will see under Notifications that Collect diagnostics initiated.

Allow some time, you may check the status by clicking on Device diagnostics under same Device.
We can see the Status showing as Pending diagnostics upload. If device is online and reporting back to the portal, it should collect the logs within next 20 mins.

You might see the error as Failed with following message:
The diagnostic upload failed because it timed out. This is a known issue for devices that don't have the Windows KB4601315 or KB4601319 installed.
Following steps are recommended for it:
Make sure to install either KB4601315 or KB4601319 based on the OS type. Then, reboot the device and retry.

Once above pre-requisite is met, you will be able to see the Device diagnostics status showing as Complete and ready to Download. Click on it to download local copy of the file which is in zip format.
What is included in Device Diagnostics

Extract the content from zip file. Following information / data is collected as part of Device Diagnostics.
Registry Keys:
- HKLM\Software\Microsoft\IntuneManagementExtension
- HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
- HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall
- HKLM\Software\Policies
- HKLM\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL
- HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
- HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
- HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
Commands:
- %programfiles%\windows defender\mpcmdrun.exe -GetFiles
- %windir%\system32\certutil.exe -store
- %windir%\system32\certutil.exe -store -user my
- %windir%\system32\Dsregcmd.exe /status
- %windir%\system32\ipconfig.exe /all
- %windir%\system32\mdmdiagnosticstool.exe
- %windir%\system32\msinfo32.exe /report %temp%\MDMDiagnostics\msinfo32.log
- %windir%\system32\netsh.exe advfirewall show allprofiles
- %windir%\system32\netsh.exe advfirewall show global
- %windir%\system32\netsh.exe lan show profiles
- %windir%\system32\netsh.exe winhttp show proxy
- %windir%\system32\netsh.exe wlan show profiles
- %windir%\system32\netsh.exe wlan show wlanreport
- %windir%\system32\ping.exe -n 50 localhost
- %windir%\system32\powercfg.exe /batteryreport /output %temp%\MDMDiagnostics\battery-report.html
- %windir%\system32\powercfg.exe /energy /output %temp%\MDMDiagnostics\energy-report.html
Event Viewers:
- Application
- Microsoft-Windows-AppLocker/EXE and DLL
- Microsoft-Windows-AppLocker/MSI and Script
- Microsoft-Windows-AppLocker/Packaged app-Deployment
- Microsoft-Windows-AppLocker/Packaged app-Execution
- Microsoft-Windows-AppxPackaging/Operational
- Microsoft-Windows-Bitlocker/Bitlocker Management
- Microsoft-Windows-HelloForBusiness/Operational
- Microsoft-Windows-SENSE/Operational
- Microsoft-Windows-SenseIR/Operational
- Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
- Setup
- System
Files:
- %ProgramData%\Microsoft\DiagnosticLogCSP\Collectors*.etl
- %ProgramData%\Microsoft\IntuneManagementExtension\Logs*.*
- %ProgramData%\Microsoft\Windows Defender\Support\MpSupportFiles.cab
- %ProgramData%\Microsoft\Windows\WlanReport\wlan-report-latest.html
- %temp%\MDMDiagnostics\battery-report.html
- %temp%\MDMDiagnostics\energy-report.html
- %temp%\MDMDiagnostics\mdmlogs-<Date/Time>.cab
- %temp%\MDMDiagnostics\msinfo32.log
- %windir%\ccm\logs*.log
- %windir%\ccmsetup\logs*.log
- %windir%\logs\CBS\cbs.log
- %windir%\logs\measuredboot*.*
- %windir%\Logs\WindowsUpdate*.etl
- %windir%\temp%computername%*.log
- %windir%\temp\officeclicktorun*.log
Important Links
https://docs.microsoft.com/en-us/mem/intune/remote-actions/collect-diagnostics