Intune Insights: App Metering

The App Metering feature within Intune Insights provides valuable metrics for app usage in your environment, and a potential route to significant cost savings, by allowing you to discover usage patterns in your environment on a per-user basis. The insights gained from App Metering can help you to assess application criticality and to identify applications that are not used by specific users, which in turn allows you to reclaim and reuse expensive licenses.

Availability

This feature is in Public Preview.

Intune licensing

In order to use the App Metering feature, you must have an Intune license that supports Remediations (for example, E3/E5 or Business Premium).

Limitations and known issues

Issue/limitation

Impact

Mitigation/planned fix

App Metering doesn't currently support private endpoints.

App Metering can be configured for public endpoints only.

Support for private endpoints will be added in a future release.

Role-based access control (RBAC) and permissions

Nerdio Manager roles

The Admin Nerdio Manager role is required to configure and manage App Metering.

Nerdio Manager access levels

Following the Principle of Least Privilege (PoLP), you can define one or more Nerdio Manager custom role(s) to manage and use App Metering. The following access levels allow users to manage aspects of the feature:

  • Full access within the Intune module allows the user to configure and manage App Metering.

  • Read-only access within the Intune module allows the user to view App Metering Insights data.

You must also set the Intune integration's Scripts management function to Manage, since Nerdio Manager needs the DeviceManagementScripts.ReadWrite.All permission to create the App Metering remediation scripts in Intune. See Intune Insights: Enable and configure App Metering for details.

Microsoft Entra built-in roles

You don't need any specific Entra ID or Azure roles to enable or use App Metering day-to-day. However, if the Intune Insights web app doesn't already hold the DeviceManagementScripts.Read.All Microsoft Graph permission, Nerdio Manager prompts you to grant it when you enable App Metering. Granting this permission requires a one-time sign-in as a user who can consent to Microsoft Graph application permissions, such as a Global Administrator or Privileged Role Administrator.

Additional permissions/access

Graph API permission for Intune Insights application

The Nerdio Manager Intune Insights application must hold the DeviceManagementScripts.Read.All Graph API permission to run the App Metering service, and the Intune integration itself must have its Scripts management function set to Manage (which grants DeviceManagementScripts.ReadWrite.All) so Nerdio Manager can create the remediation scripts. Nerdio Manager validates both as part of enabling the feature.

Endpoint requirements

See Supported platforms in Intune Insights: Enable and configure App Metering for the full device edition, join type, licensing, and network requirements.

Procedures

The following procedure guides you through enabling, configuring, and using the App Metering service:

Troubleshooting

The following table lists common issues with the App Metering service and suggested remediation steps.

Symptom

Remedy

The App Metering menu is visible but no tenant data is visible

  • Confirm that App Metering is enabled for the target tenant

  • Verify that the Remediations are deployed to and running on the target devices.

Some devices are missing from results

Verify that outbound HTTPS access to the App Metering service API host isn't being blocked by firewalls for the affected hosts — see Supported platforms in Intune Insights: Enable and configure App Metering.

Audit-event warnings appear in the collector heartbeat

Process Creation and Process Termination auditing must be enabled on target devices via Group Policy or Intune. The collector reports this state in its heartbeat.

Deployment considerations

Required resources

App Metering requires Intune Remediation scripts on the target devices. Nerdio Manager creates and deploys these for you automatically when you enable the feature. If you run more than one Nerdio Manager instance against the same tenant, each secondary instance needs a manually duplicated collector script — see Configure App Metering for multiple Nerdio Manager instances in Intune Insights: Enable and configure App Metering.

Scaling considerations

No additional preparation or configuration is necessary when deploying App Metering at scale.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.