Lesson 3 — Understanding Device Inventory
Device Inventory is the central list of devices known to Microsoft Defender for Endpoint.
It helps analysts understand which endpoints are onboarded, recently active, exposed, at risk or in need of investigation.
This lesson explains how to read the inventory, apply filters, interpret device status and pivot from a device record into deeper security evidence.
What you will learn
This lesson explains how Device Inventory supports endpoint visibility, prioritisation and investigation.
Learning objectives
After completing this lesson, you should be able to use Device Inventory as a starting point for endpoint visibility and investigation.
- Explain the purpose of Device Inventory.
- Identify the most useful device columns and status indicators.
- Interpret device risk, exposure and sensor health.
- Use search, filters, tags and device groups.
- Pivot from an inventory record into the device page and timeline.
The problem this solves
Large environments may contain hundreds or thousands of endpoints with different operating systems, owners, locations and security states.
Device Inventory gives analysts one place to identify what is present, what is active and what needs attention.
What is Device Inventory?
Device Inventory is the central device list within Microsoft Defender for Endpoint.
It combines onboarding information, discovery data, device health, risk, exposure and operating system details so analysts can quickly understand the endpoint estate.
Do not treat Device Inventory as a static asset register. It is an operational security view that helps you prioritise devices before opening a deeper investigation.
How Device Inventory supports an investigation
Onboarded devices
Onboarded devices have the Defender for Endpoint sensor or supported integration actively reporting security telemetry.
These devices provide the richest investigation detail and support direct endpoint response actions.
Discovered devices
Device discovery can identify unmanaged or partially managed devices that appear on the network.
These records help security teams find assets that may otherwise be missing from the managed endpoint estate.
Device name
The device name is often the first search field used by an analyst.
Confirm that the hostname matches the expected asset, because renamed, rebuilt or duplicate devices can create confusion during an investigation.
Operating system
The operating system column helps analysts separate Windows clients, Windows servers, macOS, Linux and other supported device types.
Operating system context is important because available telemetry, exposure and response actions may differ by platform.
Risk level
Device risk reflects active security signals associated with the endpoint.
A high-risk device may have alerts, suspicious activity or other evidence that requires immediate investigation.
Exposure level
Exposure reflects weaknesses that could make a device easier to compromise, such as vulnerable software, missing updates or insecure configuration.
Risk asks what may already be happening. Exposure asks how susceptible the device is to future attack.
Risk versus exposure
| Risk | Exposure |
|---|---|
| Indicates current or recent security concern. | Indicates weaknesses that increase attack likelihood. |
| Often influenced by active alerts and suspicious behaviour. | Often influenced by vulnerabilities and configuration issues. |
| Useful for immediate incident prioritisation. | Useful for remediation and attack-surface reduction. |
| May change rapidly during an investigation. | May remain until software or configuration is remediated. |
Last seen
The last seen value shows when Defender most recently received activity or status from the device.
An unexpectedly old timestamp can indicate that the device is offline, retired, disconnected or no longer reporting correctly.
Sensor health
Sensor health helps confirm whether the Defender for Endpoint sensor is operating and communicating normally.
A device can exist in inventory while still having degraded or inactive reporting.
Onboarding status
Onboarding status helps distinguish fully protected endpoints from discovered, unsupported, excluded or incorrectly configured devices.
This is especially useful when validating deployment coverage.
Device tags
Tags can identify business function, location, sensitivity, ownership or operational importance.
Well-designed tags make filtering and prioritisation much faster during an incident.
Device groups
Device groups organise endpoints for access control, automation and operational management.
They can help separate servers, executive devices, production systems or regional assets.
Device value
Some devices are more important to the organisation than others.
Domain controllers, privileged access workstations, finance systems and production servers may deserve higher investigation priority even when alert severity appears similar.
Search and filtering
Use search and filters to narrow the inventory by hostname, risk, exposure, operating system, onboarding status, health, tags or device group.
Filtering is often faster than manually browsing a large device list.
Customising columns
Adjust visible columns to match the investigation task.
For incident triage, prioritise risk, active alerts and last seen. For deployment review, prioritise onboarding status, sensor health and operating system.
Example triage workflow
Opening the device page
Selecting a device opens the detailed device page.
This is where the analyst can review alerts, logged-on users, timeline activity, vulnerabilities, software inventory and response options.
Device timeline relationship
Device Inventory helps you locate and prioritise the endpoint.
The device timeline then shows the chronological security activity needed to understand what happened on that endpoint.
Software and vulnerabilities
Inventory records can lead into software inventory and vulnerability information for the selected endpoint.
This helps determine whether the attack path involved outdated or exposed software.
Active alerts
A device with active alerts should be reviewed in the context of its parent Defender XDR incident.
The endpoint may be one part of a larger identity, email or cloud attack sequence.
Stale devices
Old inventory records may represent decommissioned devices, rebuilt endpoints or systems that have stopped reporting.
Do not assume every record represents a currently active and protected device.
Duplicate or renamed devices
A rebuilt or renamed computer may appear as more than one inventory record.
Use identifiers, timestamps and device history to confirm that you are investigating the correct endpoint.
Common mistake
A common mistake is sorting only by risk and ignoring business importance.
A medium-risk domain controller may deserve faster action than a high-risk test workstation.
Another common mistake
Do not assume an inventory entry means the sensor is healthy.
Always check onboarding state, last seen activity and sensor health before relying on the available telemetry.
Agent Foskett investigation tip
Use Device Inventory to find and prioritise the endpoint, then pivot into alerts, timeline activity, users, software and vulnerabilities to build the investigation story.
Best practices
- Review risk and exposure together.
- Check last seen and sensor health.
- Use tags and groups consistently.
- Prioritise critical business devices.
- Open the device page for deeper evidence.
- Review the parent Defender XDR incident.
Agent Foskett takeaway
Device Inventory is more than a list of computers.
It is the operational starting point for understanding endpoint coverage, health, exposure, active risk and the devices that require investigation first.
Related Agent Foskett learning
Continue learning
Microsoft Defender for Endpoint Device Inventory
Device Inventory in Microsoft Defender for Endpoint provides a central view of onboarded and discovered devices, including risk, exposure, operating system, last seen activity, sensor health, tags and onboarding status.
Defender for Endpoint Lesson 3
This Agent Foskett Defender for Endpoint Academy lesson explains how analysts search, filter and prioritise devices before pivoting into alerts, device timelines, software inventory, vulnerabilities and endpoint response actions.
