App Metering is an Intune Insights feature that tracks application usage across your Intune-managed Windows devices. It reports which metered applications are in use, on how many devices, by how many users, and for how long. You can view the results in Nerdio Manager under Insights > Intune > App Metering.
App Metering collects its data using two Intune remediation script packages that run on each targeted device. You can enable App Metering and deploy these scripts directly from the Nerdio Manager interface, without creating them manually in Intune.
Note
App Metering is currently in Public Preview.
When you enable App Metering, Nerdio Manager creates two remediation script packages in the Intune tenant and assigns them to the Entra ID device groups you select. A device must run both packages before it can report usage data.
|
Script package |
Purpose |
Naming |
|---|---|---|
|
Certificate script ( |
Detects whether a valid Nerdio device gateway certificate is present on the device, and generates a self-signed certificate if not. The certificate secures communication between the device and Intune Insights. |
Fixed name. Every Nerdio Manager instance in the tenant shares one certificate script. Do not rename it. |
|
Collector script ( |
Collects process start and stop events on the device, filters them against the metered application rules you configure in App Metering Settings, and sends the results to Intune Insights. |
Unique per Nerdio Manager instance. Nerdio Manager appends a suffix that identifies the instance that created it, for example |
Nerdio Manager creates both packages with the following settings.
Important
Do not make changes to these packages in the Intune portal.
|
Setting |
Value |
|---|---|
|
Run this script using the logged-on credentials |
No |
|
Enforce script signature check |
No |
|
Run script in 64-bit PowerShell |
Yes |
|
Schedule |
Every 1 hour |
|
Author (as shown in the Intune admin center) |
Nerdio Manager |
Note
If a remediation named Nerdio-SWM-Certificate already exists in the tenant — for example, because you configured App Metering manually during the private preview — Nerdio Manager reuses it rather than creating a second one. It keeps any assignments already on that script, and adds its own assignments alongside them. Nerdio Manager never deletes a pre-existing certificate script.
Before you enable App Metering, ensure the following:
-
You've enabled Intune Insights in Nerdio Manager. You can only enable App Metering for an Intune tenant that already has Intune Insights deployed. For details, see Insights: Intune.
-
The Intune integration has the Scripts management function set to Manage. Nerdio Manager requires the
DeviceManagementScripts.ReadWrite.Allpermission to create remediation scripts in Intune. Enabling App Metering validates this permission and returns an error if you haven't set it. To check the setting, navigate to Settings > Integrations > Intune > Configure and review the Scripts function. For details, see Intune: Granular permissions. -
The Intune Insights web app has the
DeviceManagementScripts.Read.AllMicrosoft Graph permission. If this permission is missing, Nerdio Manager prompts you to add it when you enable App Metering. Sign in as a user who can grant Microsoft Graph application permissions, such as a Global Administrator or Privileged Role Administrator. -
Your target devices support Intune Remediations. See Supported platforms below for the edition, join type, and licence requirements. You must also enable Process Creation and Process Termination auditing on the target devices, through Group Policy or an Intune policy, so Windows records process start and stop events in the Security event log.
-
You have Entra ID device groups that contain the devices you want to meter. App Metering assigns the remediation scripts to the groups you select; Nerdio Manager doesn't create or manage the group membership itself.
Nerdio Manager supports App Metering on any Intune-managed Windows device that supports Intune Remediations. Since both App Metering scripts are Remediation script packages, Remediation support is a requirement for the feature: a device that can't run Remediations can't be metered.
Microsoft sets the requirements for Remediations. At the time of writing, a device must be Microsoft Entra joined or Microsoft Entra hybrid joined, and either MDM-enrolled in Intune running Windows Enterprise, Professional or Education edition, or co-managed with Configuration Manager.
Each device's user must also hold one of the following licences, which include Remediation support:
-
Windows Enterprise E3 or E5, included in Microsoft 365 F3, E3 and E5
-
Windows Education A3 or A5, included in Microsoft 365 A3 and A5
-
Windows Virtual Desktop Access (VDA) per user
Caution
Microsoft may change the platform and licensing requirements for Remediations at any time. Before you enable App Metering, confirm the current requirements in the Microsoft Learn article Use Remediations to detect and fix support issues, linked under Related articles below. If a device doesn't meet them, it won't run the App Metering scripts, and Nerdio Manager omits it from usage results without error.
App Metering doesn't support non-Windows devices, such as macOS, iOS and Android, or Windows devices that aren't Entra joined or hybrid joined.
App Metering also depends on outbound access to two API endpoints. Devices reach these directly; you don't need to open any inbound connection.
|
Endpoint |
Purpose |
|---|---|
|
|
Hourly fetch of the per-tenant allow list of apps to track |
|
|
Submission of app start/stop sessions and a heartbeat with collector status |
A per-device certificate that the Remediations provision signs and authenticates both endpoints, so App Metering needs no additional Microsoft Graph permissions beyond those you've already granted for Intune integration.
You can enable App Metering either as part of a new Intune Insights deployment, or at any time afterwards from the App Metering dialog for an existing deployment.
To enable App Metering as part of a new Intune Insights deployment:-
Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, navigate to Intune Insights, and select the Disabled toggle.
-
In the Enable Intune Insights dialog box, complete the resource, resource name, and tag sections as described in Insights: Intune.
-
Below the tag section, expand the App Metering section.
-
Set App metering to Enabled.
-
In Collector script target groups, search for and select the Entra ID device groups you want to meter with this Nerdio Manager instance.
-
In Certificate script target groups, search for and select every Entra ID device group that any Nerdio Manager instance in this tenant will meter. This must include, at a minimum, the groups you selected for the collector script — see Configure App Metering for multiple Nerdio Manager instances below.
-
Select Enable.
This deploys Intune Insights and enables App Metering in the same operation.
-
Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, and navigate to Intune Insights.
-
On the Intune tenant row, open the action menu and select App metering.
-
In the App Metering dialog box, set App metering to Enabled.
-
In Collector script target groups, search for and select the Entra ID device groups you want to meter with this Nerdio Manager instance.
-
In Certificate script target groups, search for and select every Entra ID device group that any Nerdio Manager instance in this tenant will meter. This must include, at a minimum, the groups you selected for the collector script.
The Collector and Certificate script target groups fields are independent, so you can assign a broader set of groups to the shared certificate script than the set you meter with this specific instance.
-
Select Save.
|
Control |
Description |
|---|---|
|
App metering |
Enables App Metering for this Intune tenant. When you enable it, Nerdio Manager validates the required permissions, creates the certificate and collector remediation scripts in Intune, assigns them to the groups you selected, and turns on App Metering in Intune Insights. |
|
Collector script target groups |
The Entra ID device groups the collector script is assigned to. Select the device groups in your primary tenant you want to meter with this Nerdio Manager instance. Nerdio Manager only collects usage data from devices in these groups. |
|
Certificate script target groups |
The Entra ID device groups the shared certificate script is assigned to. Select every group that's in scope for App Metering across all Nerdio Manager instances that use this tenant. A device that receives the collector script but not the certificate script can't report usage data. |
When you select Save or Enable, Nerdio Manager runs a task that performs the following steps:
-
Validates that the Intune integration has the Scripts function set to Manage. If it doesn't, the task fails with an error describing the missing permission.
-
Checks that the Intune Insights web app has the
DeviceManagementScripts.Read.Allpermission, and prompts you to add it if it's missing. -
Creates the
Nerdio-SWM-Certificateremediation script in Intune, or reuses it if a script of that name already exists. -
Creates the
Nerdio-SWM-Collector-<suffix>remediation script for this Nerdio Manager instance. -
Assigns each script to the target groups you selected.
-
Enables App Metering on the Intune Insights tenant.
You can confirm the result in the Intune admin center. Under Devices > Scripts and remediations > Remediations, both packages show a status of Active.
The Intune Insights status tooltip in Nerdio Manager now includes an App metering: Enabled line.
Nerdio Manager doesn't display application usage immediately after you enable App Metering. Each device must receive both remediation scripts from Intune, run them on the 12-hour schedule, and report its first collection before it appears in the App Metering tab.
Note
Allow a minimum of 24 hours after you enable App Metering before application details appear in Nerdio Manager.
Devices that are offline, or that don't check in with Intune during this period, can take considerably longer to appear. A device is only metered once it comes online, receives the scripts, and completes at least one collection cycle.
In the App Metering section of Intune Insights, you can add, edit, and remove metered apps.
Until you configure at least one application, the collector script has no rules to match and doesn't record any usage. Newly added applications are subject to the same discovery time as initial enablement: allow at least 24 hours before their usage appears.
To add an application to App Metering:-
Navigate to Insights > Intune, and select App Metering from the top menu.
-
Select App Metering Settings.
-
Select the App Metering Enabled button for the target tenant to enter its configuration menu.
Note
If App Metering Enabled doesn't appear for the tenant, you haven't enabled App Metering, or it's misconfigured. See Enable App Metering above, or Intune Insights: App Metering for troubleshooting.
-
Select Add App.
-
Enter the required information:
-
App Name (required), e.g.
Google Chrome. -
Enabled toggle to start/stop tracking this app without deleting it.
-
Detection Rules: one or more rules that decide whether a running process should be counted. Each rule has a type and a pattern:
-
Process Name: matches the executable file name (e.g.
chrome.exe). -
Exact Path: matches the full path on disk (e.g.
C:\Program Files\Google\Chrome\Application\chrome.exe). -
Regex: matches the full path against a regular expression (e.g.
(?i)chrome\.exe$). Add as many rules as you need — a process matches if any rule matches.
Select Add Rule to add more detection rules, or select the x icon for a given rule to remove it.
-
-
-
Select Done to save the app, then Save to apply your changes to the tenant settings.
-
Navigate to Insights > Intune, and select App Metering from the top menu.
-
Select App Metering Settings.
-
Select the App Metering Enabled button for the target tenant to enter its configuration menu.
-
Select the Enabled button for the app to open its configuration dialog and amend its settings:
-
To temporarily disable metering for the app, toggle the Enabled switch off.
-
To change how the app is detected on target devices, add or modify Detection Rules (see above for details).
-
-
Select Done to save the app, then Save to apply your changes to the tenant settings.
-
Navigate to Insights > Intune, and select App Metering from the top menu.
-
Select App Metering Settings.
-
Select the App Metering Enabled button for the target tenant to enter its configuration menu.
-
Select the trashcan icon for the app to delete its configuration.
Note
If you plan to re-add the app to App Metering in the future, we recommend that you temporarily disable monitoring for it rather than deleting it.
Once you've begun collecting metering data for an app, you can view a number of different usage metrics for it across a configurable time period.
To view metering data for an app:-
Navigate to Insights > Intune, and select App Metering from the top menu.
A list of monitored apps displays, sorted by tenant.
-
Select the app whose metrics you want to view.
-
Use the drop-down menu to select the time period you want to report for (the default is the last 30 days).
The main viewing pane shows the total number of devices and users for the period, and metrics for average hours spent in the app per user.
-
Use the tabs to display usage statistics and last-used date for the app by user, by device, or by version.
-
To export the data to your local device for further analysis, select Export as CSV.
You can run more than one Nerdio Manager instance against a single Entra ID and Intune tenant — for example, a production instance and a secondary instance for a separate business unit. App Metering supports this, but the two remediation scripts behave differently, so plan your target groups accordingly.
|
Certificate script |
Collector script |
|
|---|---|---|
|
Scope |
One per tenant, shared by every Nerdio Manager instance. All instances use the same certificate. |
One per Nerdio Manager instance. Each instance requires its own collector with a unique name. |
|
Created by |
The first Nerdio Manager instance to enable App Metering. Subsequent instances reuse it. |
The primary Nerdio Manager instance, from the App Metering dialog. Each secondary instance requires a copy you create manually in Intune with its own Intune Insights URL. |
|
Target groups |
Every device group in scope for App Metering across all Nerdio Manager instances in the tenant. |
Only the device groups this specific instance should meter. |
Because the certificate script is shared, its target groups must cover every Nerdio Manager instance that will meter devices in the tenant. In the App Metering dialog of your primary instance, set Certificate script target groups to include the device groups the primary instance uses and the device groups each secondary instance uses. If you add a secondary instance later, return to this dialog and add its groups to the certificate script assignment.
Important
Don't create additional certificate scripts, and don't rename Nerdio-SWM-Certificate. Intune Insights expects exactly this name, and a second certificate script would issue a different certificate to the same devices.
A single Nerdio Manager instance owns each collector script. The detection script contains the address of that instance's Intune Insights web app, and every device that runs it reports usage to that address. For this reason, you can't share a collector: a second instance needs its own copy of the collector, pointing at its own Intune Insights web app.
From the Nerdio Manager interface, you can only create and assign the collector script for the primary instance. To meter devices with a secondary Nerdio Manager instance, duplicate the collector remediation in Intune and change its URL as follows.
Step 1: Find the secondary instance's Intune Insights web app URLSign in to the secondary Nerdio Manager instance and navigate to Settings > Integrations > Intune > Intune Insights. Note the URL of the Intune Insights app service deployed for that instance, for example https://nmw-ii-app-xxxxx.azurewebsites.net.
Important
Use the address of the Intune Insights web app, not the address of the Nerdio Manager instance itself. If a web application firewall or Azure Front Door publishes the Intune Insights web app, use the address devices reach it on, not the underlying App Service address.
The collector remediation consists of two PowerShell files: a detection script, Detect-SwmEvents.ps1, which performs all of the collection work, and a remediation script, Remediate-SwmEvents.ps1, which performs no action. These are the same files Nerdio Manager uploaded for the primary instance. If you don't have a copy, contact the Nerdio Manager support team.
Open Detect-SwmEvents.ps1 in a text editor. Near the top of the file, in the Configuration section, locate the line that sets the API base URL:
$ApiBaseUrl = "https://nmw-ii-app-xxxxx.azurewebsites.net"
Replace the value with the URL of the secondary instance's Intune Insights web app from Step 1, keeping the https:// prefix and the surrounding quotation marks. Save the file. Don't make any other changes to either script.
Note
This is the only value that differs between collector scripts for different Nerdio Manager instances. The two endpoints the script calls, /device-gateway/v2/swm-rules and /device-gateway/v2/ingest, are built from this base URL. Devices must be able to reach the new address on outbound port 443.
-
In the Intune admin center, navigate to Devices > Scripts and remediations > Remediations and select Create.
-
Enter a unique name that identifies the secondary instance, for example
Nerdio-SWM-Collector-<secondary instance name>. Don't reuse the primary instance's collector name. -
Upload the edited
Detect-SwmEvents.ps1as the detection script file, andRemediate-SwmEvents.ps1as the remediation script file. -
Set Run this script using the logged-on credentials to No, Enforce script signature check to No, and Run script in 64-bit PowerShell to Yes.
-
Assign the remediation to the Entra ID device groups for the secondary Nerdio Manager instance, with a schedule of Every 12 hours.
-
Confirm that the primary instance's Certificate script target groups includes these same device groups, so the shared certificate script also reaches them.
-
Allow a minimum of 24 hours for devices in the secondary instance's groups to appear in that instance's App Metering tab. Offline devices take longer.
Note
Nerdio Manager only manages the scripts it created. It doesn't modify or remove a manually created collector script when you disable App Metering from the primary instance, and a manually created collector doesn't appear in the primary instance's App Metering dialog. If Nerdio publishes an updated collector script, you must update the manually created copy by hand.
For help configuring App Metering across multiple Nerdio Manager instances, contact the Nerdio Manager support team.
To disable App Metering while keeping Intune Insights enabled:
-
Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, and navigate to Intune Insights.
-
On the Intune tenant row, open the action menu and select App metering.
-
Set App metering to Disabled and select Save.
Disabling Intune Insights also automatically disables App Metering.
When you disable App Metering, Nerdio Manager removes the remediation scripts and assignments it created. It leaves the following untouched:
-
A
Nerdio-SWM-Certificatescript that existed before you enabled App Metering from Nerdio Manager, and any assignments on it that you made outside Nerdio Manager. -
Assignments you added to any script manually in the Intune admin center.
-
Collector scripts you duplicated manually for secondary Nerdio Manager instances.
As of its Public Preview release, App Metering is configured entirely within the Nerdio Manager interface. If you previously set up the Private Preview version of App Metering via direct configuration in the Azure portal, you can switch to native Nerdio Manager management of the feature by following the steps in Enable App Metering above.
When you perform this switch:
-
Nerdio Manager reuses your existing
Nerdio-SWM-Certificatescript. It keeps its existing assignments, which appear pre-selected in Certificate script target groups. -
Nerdio Manager creates a new collector script with an instance-specific suffix. Your manually created collector remediation stays in place, so the same devices may briefly run two collectors. Once you've confirmed the new collector is Active in Intune, remove the manually created collector remediation to avoid duplicate collection.
Important
You can find the collector script you created during Private Preview within the Intune console, at Manage devices > Scripts and remediations. Do not delete any scripts with the author
Nerdio Manager; any such scripts have been automatically created by Nerdio Manager as part of provisioning Intune functionality (including App Metering), and removing or altering these scripts may render Nerdio Manager features inoperable.
Comments (0 comments)