Agent Foskett Academy • Defender for Endpoint • Module 1 • Lesson 3

Lesson 3 — Understanding Device Inventory

Device Inventory is the central list of devices known to Microsoft Defender for Endpoint.

It helps analysts understand which endpoints are onboarded, recently active, exposed, at risk or in need of investigation.

This lesson explains how to read the inventory, apply filters, interpret device status and pivot from a device record into deeper security evidence.

Device Inventory tells you what devices exist, how healthy they are and which ones deserve attention first.
Agent Foskett Microsoft Defender for Endpoint Device Inventory lesson
What you will learn

This lesson explains how Device Inventory supports endpoint visibility, prioritisation and investigation.

What Device Inventory contains
How to interpret risk and exposure
How to use filters, tags and groups
How to pivot into a device investigation

Learning objectives

After completing this lesson, you should be able to use Device Inventory as a starting point for endpoint visibility and investigation.

  • Explain the purpose of Device Inventory.
  • Identify the most useful device columns and status indicators.
  • Interpret device risk, exposure and sensor health.
  • Use search, filters, tags and device groups.
  • Pivot from an inventory record into the device page and timeline.

The problem this solves

Large environments may contain hundreds or thousands of endpoints with different operating systems, owners, locations and security states.

Device Inventory gives analysts one place to identify what is present, what is active and what needs attention.

What is Device Inventory?

Device Inventory is the central device list within Microsoft Defender for Endpoint.

It combines onboarding information, discovery data, device health, risk, exposure and operating system details so analysts can quickly understand the endpoint estate.

Agent Foskett tip:

Do not treat Device Inventory as a static asset register. It is an operational security view that helps you prioritise devices before opening a deeper investigation.

How Device Inventory supports an investigation

Device Inventory ├── Find the endpoint ├── Review risk and exposure ├── Check last seen and sensor health ├── Confirm operating system and tags └── Open the device page │ ▼ Device Investigation ├── Review active alerts ├── Examine the device timeline ├── Check logged-on users ├── Inspect software and vulnerabilities └── Perform response actions

Onboarded devices

Onboarded devices have the Defender for Endpoint sensor or supported integration actively reporting security telemetry.

These devices provide the richest investigation detail and support direct endpoint response actions.

Discovered devices

Device discovery can identify unmanaged or partially managed devices that appear on the network.

These records help security teams find assets that may otherwise be missing from the managed endpoint estate.

Device name

The device name is often the first search field used by an analyst.

Confirm that the hostname matches the expected asset, because renamed, rebuilt or duplicate devices can create confusion during an investigation.

Operating system

The operating system column helps analysts separate Windows clients, Windows servers, macOS, Linux and other supported device types.

Operating system context is important because available telemetry, exposure and response actions may differ by platform.

Risk level

Device risk reflects active security signals associated with the endpoint.

A high-risk device may have alerts, suspicious activity or other evidence that requires immediate investigation.

Exposure level

Exposure reflects weaknesses that could make a device easier to compromise, such as vulnerable software, missing updates or insecure configuration.

Risk asks what may already be happening. Exposure asks how susceptible the device is to future attack.

Risk versus exposure

RiskExposure
Indicates current or recent security concern.Indicates weaknesses that increase attack likelihood.
Often influenced by active alerts and suspicious behaviour.Often influenced by vulnerabilities and configuration issues.
Useful for immediate incident prioritisation.Useful for remediation and attack-surface reduction.
May change rapidly during an investigation.May remain until software or configuration is remediated.

Last seen

The last seen value shows when Defender most recently received activity or status from the device.

An unexpectedly old timestamp can indicate that the device is offline, retired, disconnected or no longer reporting correctly.

Sensor health

Sensor health helps confirm whether the Defender for Endpoint sensor is operating and communicating normally.

A device can exist in inventory while still having degraded or inactive reporting.

Onboarding status

Onboarding status helps distinguish fully protected endpoints from discovered, unsupported, excluded or incorrectly configured devices.

This is especially useful when validating deployment coverage.

Device tags

Tags can identify business function, location, sensitivity, ownership or operational importance.

Well-designed tags make filtering and prioritisation much faster during an incident.

Device groups

Device groups organise endpoints for access control, automation and operational management.

They can help separate servers, executive devices, production systems or regional assets.

Device value

Some devices are more important to the organisation than others.

Domain controllers, privileged access workstations, finance systems and production servers may deserve higher investigation priority even when alert severity appears similar.

Search and filtering

Use search and filters to narrow the inventory by hostname, risk, exposure, operating system, onboarding status, health, tags or device group.

Filtering is often faster than manually browsing a large device list.

Customising columns

Adjust visible columns to match the investigation task.

For incident triage, prioritise risk, active alerts and last seen. For deployment review, prioritise onboarding status, sensor health and operating system.

Example triage workflow

Filter: Risk = High │ ▼ Sort by: Exposure or Active Alerts │ ▼ Check: Last Seen and Sensor Health │ ▼ Confirm: Device Tag and Business Importance │ ▼ Open Device Page │ ▼ Review Alerts, Timeline, Users and Response Actions

Opening the device page

Selecting a device opens the detailed device page.

This is where the analyst can review alerts, logged-on users, timeline activity, vulnerabilities, software inventory and response options.

Device timeline relationship

Device Inventory helps you locate and prioritise the endpoint.

The device timeline then shows the chronological security activity needed to understand what happened on that endpoint.

Software and vulnerabilities

Inventory records can lead into software inventory and vulnerability information for the selected endpoint.

This helps determine whether the attack path involved outdated or exposed software.

Active alerts

A device with active alerts should be reviewed in the context of its parent Defender XDR incident.

The endpoint may be one part of a larger identity, email or cloud attack sequence.

Stale devices

Old inventory records may represent decommissioned devices, rebuilt endpoints or systems that have stopped reporting.

Do not assume every record represents a currently active and protected device.

Duplicate or renamed devices

A rebuilt or renamed computer may appear as more than one inventory record.

Use identifiers, timestamps and device history to confirm that you are investigating the correct endpoint.

Common mistake

A common mistake is sorting only by risk and ignoring business importance.

A medium-risk domain controller may deserve faster action than a high-risk test workstation.

Another common mistake

Do not assume an inventory entry means the sensor is healthy.

Always check onboarding state, last seen activity and sensor health before relying on the available telemetry.

Agent Foskett investigation tip

Inventory tells you where to look. The timeline tells you what happened.

Use Device Inventory to find and prioritise the endpoint, then pivot into alerts, timeline activity, users, software and vulnerabilities to build the investigation story.

Best practices

  • Review risk and exposure together.
  • Check last seen and sensor health.
  • Use tags and groups consistently.
  • Prioritise critical business devices.
  • Open the device page for deeper evidence.
  • Review the parent Defender XDR incident.

Agent Foskett takeaway

Device Inventory is more than a list of computers.

It is the operational starting point for understanding endpoint coverage, health, exposure, active risk and the devices that require investigation first.

Lesson summary
Device Inventory gives analysts a central view of known endpoints, including device risk, exposure, operating system, onboarding status, sensor health, tags and last seen activity. Use it to prioritise devices, validate endpoint coverage and pivot into deeper device investigations.
Defender for Endpoint Academy

Related Agent Foskett learning

These links connect Lesson 3 with Defender for Endpoint foundations, device telemetry, timeline analysis and the wider Agent Foskett Academy.

Continue learning

Continue through the Defender for Endpoint Academy or explore the wider Agent Foskett learning library.

Microsoft Defender for Endpoint Device Inventory

Device Inventory in Microsoft Defender for Endpoint provides a central view of onboarded and discovered devices, including risk, exposure, operating system, last seen activity, sensor health, tags and onboarding status.

Defender for Endpoint Lesson 3

This Agent Foskett Defender for Endpoint Academy lesson explains how analysts search, filter and prioritise devices before pivoting into alerts, device timelines, software inventory, vulnerabilities and endpoint response actions.