table

DeviceInfo

DeviceInfo contains device inventory and state information, including operating system, onboarding, sensor health, and logged-on user details.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeLast date and time recorded for the device.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ClientVersionstringVersion of the endpoint agent or sensor running on the device.
PublicIPstringPublic IP address used by the onboarded device to connect to Microsoft Defender for Endpoint.
OSPlatformstringPlatform of the operating system running on the device.
OSBuildlongBuild version of the operating system running on the device.
LoggedOnUsersstringList of users logged on to the device at the time of the event.
OnboardingStatusstringIndicates whether the device is currently onboarded to Microsoft Defender for Endpoint.
SensorHealthStatestringHealth state of the device EDR sensor, if onboarded.