Saved & shared queries
OVERVIEW
Introducing collaboration to the Multi-Device Query experience in Microsoft Intune, Saved and Shared Queries enable Intune admins to save, organize, and share KQL queries across their organization. The feature eliminates manual copy-and-paste workflows and local file sharing, making it easier to standardize, discover, and reuse approved queries while reducing duplicate work across teams.
MY CONTRIBUTION
I owned the end-to-end design strategy for the new Device Query experience in Intune, leading the work from early exploration and user research through concept validation, prototyping, accessibility reviews, engineering handoff, and bug bashes to ensure a high-quality implementation.
THE PROBLEM
Intune admins rely on Device Query to investigate issues and analyze large device datasets. However, reusing, organizing, and sharing queries across teams required manual work, making collaboration difficult and slowing down investigations.
HOW MIGHT WE
How might we help admins efficiently create, save, edit, and share queries while ensuring consistency, discoverability and safe collaboration?
THE OUTCOME
Improved discoverability and organization of queries. Introduced an in-platform collaboration solution that streamlined workflows, reduced context switching, and improved team productivity.
Established a stronger foundation for future AI-powered analytics and reporting experiences.
Use cases
Weekly compliance reporting: Teams can reuse the same shared query, helping keep reporting consistent across users.
For non-KQL users: Regional admins can run approved saved queries without needing to write or understand KQL.
Policy updates: Changes to a shared query are reflected for everyone using it, so users always run the latest version.
Cross-device continuity: Saved queries are available across sessions and browsers, allowing users to continue investigations from different devices.
I've kept this case study high-level to respect NDA agreements. If you'd like to learn more, send me an email.
