The App Metering feature within Intune Insights provides valuable metrics for app usage in your environment, and a potential route to significant cost savings, by allowing you to discover usage patterns in your environment on a per-user basis. The insights gained from App Metering can help you to assess application criticality and to identify applications that are not used by specific users, which in turn allows you to reclaim and reuse expensive licenses.
This feature is in Public Preview.
In order to use the App Metering feature, you must have an Intune license that supports Remediations (for example, E3/E5 or Business Premium).
|
Issue/limitation |
Impact |
Mitigation/planned fix |
|---|---|---|
|
App Metering doesn't currently support private endpoints. |
App Metering can be configured for public endpoints only. |
Support for private endpoints will be added in a future release. |
The Admin Nerdio Manager role is required to configure and manage App Metering.
Following the Principle of Least Privilege (PoLP), you can define one or more Nerdio Manager custom role(s) to manage and use App Metering. The following access levels allow users to manage aspects of the feature:
-
Full access within the Intune module allows the user to configure and manage App Metering.
-
Read-only access within the Intune module allows the user to view App Metering Insights data.
You must also set the Intune integration's Scripts management function to Manage, since Nerdio Manager needs the DeviceManagementScripts.ReadWrite.All permission to create the App Metering remediation scripts in Intune. See Intune Insights: Enable and configure App Metering for details.
You don't need any specific Entra ID or Azure roles to enable or use App Metering day-to-day. However, if the Intune Insights web app doesn't already hold the DeviceManagementScripts.Read.All Microsoft Graph permission, Nerdio Manager prompts you to grant it when you enable App Metering. Granting this permission requires a one-time sign-in as a user who can consent to Microsoft Graph application permissions, such as a Global Administrator or Privileged Role Administrator.
The Nerdio Manager Intune Insights application must hold the DeviceManagementScripts.Read.All Graph API permission to run the App Metering service, and the Intune integration itself must have its Scripts management function set to Manage (which grants DeviceManagementScripts.ReadWrite.All) so Nerdio Manager can create the remediation scripts. Nerdio Manager validates both as part of enabling the feature.
See Supported platforms in Intune Insights: Enable and configure App Metering for the full device edition, join type, licensing, and network requirements.
The following procedure guides you through enabling, configuring, and using the App Metering service:
The following table lists common issues with the App Metering service and suggested remediation steps.
|
Symptom |
Remedy |
|---|---|
|
The App Metering menu is visible but no tenant data is visible |
|
|
Some devices are missing from results |
Verify that outbound HTTPS access to the App Metering service API host isn't being blocked by firewalls for the affected hosts — see Supported platforms in Intune Insights: Enable and configure App Metering. |
|
Audit-event warnings appear in the collector heartbeat |
Process Creation and Process Termination auditing must be enabled on target devices via Group Policy or Intune. The collector reports this state in its heartbeat. |
App Metering requires Intune Remediation scripts on the target devices. Nerdio Manager creates and deploys these for you automatically when you enable the feature. If you run more than one Nerdio Manager instance against the same tenant, each secondary instance needs a manually duplicated collector script — see Configure App Metering for multiple Nerdio Manager instances in Intune Insights: Enable and configure App Metering.
Contact our Sales team for more information about this feature.
Raise a support ticket about this feature.
Comments (0 comments)