Intune Insights: Enable and configure App Metering

App Metering is an Intune Insights feature that tracks application usage across your Intune-managed Windows devices. It reports which metered applications are in use, on how many devices, by how many users, and for how long. You can view the results in Nerdio Manager under Insights > Intune > App Metering.

App Metering collects its data using two Intune remediation script packages that run on each targeted device. You can enable App Metering and deploy these scripts directly from the Nerdio Manager interface, without creating them manually in Intune.

Note

App Metering is currently in Public Preview.

How App Metering works

When you enable App Metering, Nerdio Manager creates two remediation script packages in the Intune tenant and assigns them to the Entra ID device groups you select. A device must run both packages before it can report usage data.

Script package

Purpose

Naming

Certificate script (Nerdio-SWM-Certificate)

Detects whether a valid Nerdio device gateway certificate is present on the device, and generates a self-signed certificate if not. The certificate secures communication between the device and Intune Insights.

Fixed name. Every Nerdio Manager instance in the tenant shares one certificate script. Do not rename it.

Collector script (Nerdio-SWM-Collector-<suffix>)

Collects process start and stop events on the device, filters them against the metered application rules you configure in App Metering Settings, and sends the results to Intune Insights.

Unique per Nerdio Manager instance. Nerdio Manager appends a suffix that identifies the instance that created it, for example Nerdio-SWM-Collector-nmw-ii-app.

Nerdio Manager creates both packages with the following settings. 

Important

Do not make changes to these packages in the Intune portal.

Setting

Value

Run this script using the logged-on credentials

No

Enforce script signature check

No

Run script in 64-bit PowerShell

Yes

Schedule

Every 1 hour

Author (as shown in the Intune admin center)

Nerdio Manager 

Note

If a remediation named Nerdio-SWM-Certificate already exists in the tenant — for example, because you configured App Metering manually during the private preview — Nerdio Manager reuses it rather than creating a second one. It keeps any assignments already on that script, and adds its own assignments alongside them. Nerdio Manager never deletes a pre-existing certificate script.

Prerequisites

Before you enable App Metering, ensure the following:

  • You've enabled Intune Insights in Nerdio Manager. You can only enable App Metering for an Intune tenant that already has Intune Insights deployed. For details, see Insights: Intune.

  • The Intune integration has the Scripts management function set to Manage. Nerdio Manager requires the DeviceManagementScripts.ReadWrite.All permission to create remediation scripts in Intune. Enabling App Metering validates this permission and returns an error if you haven't set it. To check the setting, navigate to Settings > Integrations > Intune > Configure and review the Scripts function. For details, see Intune: Granular permissions.

  • The Intune Insights web app has the DeviceManagementScripts.Read.All Microsoft Graph permission. If this permission is missing, Nerdio Manager prompts you to add it when you enable App Metering. Sign in as a user who can grant Microsoft Graph application permissions, such as a Global Administrator or Privileged Role Administrator.

  • Your target devices support Intune Remediations. See Supported platforms below for the edition, join type, and licence requirements. You must also enable Process Creation and Process Termination auditing on the target devices, through Group Policy or an Intune policy, so Windows records process start and stop events in the Security event log.

  • You have Entra ID device groups that contain the devices you want to meter. App Metering assigns the remediation scripts to the groups you select; Nerdio Manager doesn't create or manage the group membership itself.

Supported platforms

Nerdio Manager supports App Metering on any Intune-managed Windows device that supports Intune Remediations. Since both App Metering scripts are Remediation script packages, Remediation support is a requirement for the feature: a device that can't run Remediations can't be metered.

Microsoft sets the requirements for Remediations. At the time of writing, a device must be Microsoft Entra joined or Microsoft Entra hybrid joined, and either MDM-enrolled in Intune running Windows Enterprise, Professional or Education edition, or co-managed with Configuration Manager.

Each device's user must also hold one of the following licences, which include Remediation support:

  • Windows Enterprise E3 or E5, included in Microsoft 365 F3, E3 and E5

  • Windows Education A3 or A5, included in Microsoft 365 A3 and A5

  • Windows Virtual Desktop Access (VDA) per user

Caution

Microsoft may change the platform and licensing requirements for Remediations at any time. Before you enable App Metering, confirm the current requirements in the Microsoft Learn article Use Remediations to detect and fix support issues, linked under Related articles below. If a device doesn't meet them, it won't run the App Metering scripts, and Nerdio Manager omits it from usage results without error.

App Metering doesn't support non-Windows devices, such as macOS, iOS and Android, or Windows devices that aren't Entra joined or hybrid joined.

App Metering also depends on outbound access to two API endpoints. Devices reach these directly; you don't need to open any inbound connection.

Endpoint

Purpose

/device-gateway/v2/swm-rules 

Hourly fetch of the per-tenant allow list of apps to track

/device-gateway/v2/ingest 

Submission of app start/stop sessions and a heartbeat with collector status

A per-device certificate that the Remediations provision signs and authenticates both endpoints, so App Metering needs no additional Microsoft Graph permissions beyond those you've already granted for Intune integration.

Enable App Metering

You can enable App Metering either as part of a new Intune Insights deployment, or at any time afterwards from the App Metering dialog for an existing deployment.

To enable App Metering as part of a new Intune Insights deployment:
  1. Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, navigate to Intune Insights, and select the Disabled toggle.

  2. In the Enable Intune Insights dialog box, complete the resource, resource name, and tag sections as described in Insights: Intune.

  3. Below the tag section, expand the App Metering section.

  4. Set App metering to Enabled.

  5. In Collector script target groups, search for and select the Entra ID device groups you want to meter with this Nerdio Manager instance.

  6. In Certificate script target groups, search for and select every Entra ID device group that any Nerdio Manager instance in this tenant will meter. This must include, at a minimum, the groups you selected for the collector script — see Configure App Metering for multiple Nerdio Manager instances below.

  7. Select Enable.

    This deploys Intune Insights and enables App Metering in the same operation.

To enable App Metering on an existing Intune Insights deployment:
  1. Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, and navigate to Intune Insights.

  2. On the Intune tenant row, open the action menu and select App metering.

  3. In the App Metering dialog box, set App metering to Enabled.

  4. In Collector script target groups, search for and select the Entra ID device groups you want to meter with this Nerdio Manager instance.

  5. In Certificate script target groups, search for and select every Entra ID device group that any Nerdio Manager instance in this tenant will meter. This must include, at a minimum, the groups you selected for the collector script.

    The Collector and Certificate script target groups fields are independent, so you can assign a broader set of groups to the shared certificate script than the set you meter with this specific instance.

  6. Select Save.

App Metering dialog box reference

Control

Description

App metering

Enables App Metering for this Intune tenant. When you enable it, Nerdio Manager validates the required permissions, creates the certificate and collector remediation scripts in Intune, assigns them to the groups you selected, and turns on App Metering in Intune Insights.

Collector script target groups

The Entra ID device groups the collector script is assigned to. Select the device groups in your primary tenant you want to meter with this Nerdio Manager instance. Nerdio Manager only collects usage data from devices in these groups.

Certificate script target groups

The Entra ID device groups the shared certificate script is assigned to. Select every group that's in scope for App Metering across all Nerdio Manager instances that use this tenant. A device that receives the collector script but not the certificate script can't report usage data.

What happens after you enable App Metering

When you select Save or Enable, Nerdio Manager runs a task that performs the following steps:

  1. Validates that the Intune integration has the Scripts function set to Manage. If it doesn't, the task fails with an error describing the missing permission.

  2. Checks that the Intune Insights web app has the DeviceManagementScripts.Read.All permission, and prompts you to add it if it's missing.

  3. Creates the Nerdio-SWM-Certificate remediation script in Intune, or reuses it if a script of that name already exists.

  4. Creates the Nerdio-SWM-Collector-<suffix> remediation script for this Nerdio Manager instance.

  5. Assigns each script to the target groups you selected.

  6. Enables App Metering on the Intune Insights tenant.

You can confirm the result in the Intune admin center. Under Devices > Scripts and remediations > Remediations, both packages show a status of Active.

The Intune Insights status tooltip in Nerdio Manager now includes an App metering: Enabled line.

Discovery time

Nerdio Manager doesn't display application usage immediately after you enable App Metering. Each device must receive both remediation scripts from Intune, run them on the 12-hour schedule, and report its first collection before it appears in the App Metering tab.

Note

Allow a minimum of 24 hours after you enable App Metering before application details appear in Nerdio Manager.

Devices that are offline, or that don't check in with Intune during this period, can take considerably longer to appear. A device is only metered once it comes online, receives the scripts, and completes at least one collection cycle.

Add and configure metered apps

In the App Metering section of Intune Insights, you can add, edit, and remove metered apps.

Until you configure at least one application, the collector script has no rules to match and doesn't record any usage. Newly added applications are subject to the same discovery time as initial enablement: allow at least 24 hours before their usage appears.

To add an application to App Metering:
  1. Navigate to Insights > Intune, and select App Metering from the top menu.

  2. Select App Metering Settings.

  3. Select the App Metering Enabled button for the target tenant to enter its configuration menu.

    Note

    If App Metering Enabled doesn't appear for the tenant, you haven't enabled App Metering, or it's misconfigured. See Enable App Metering above, or Intune Insights: App Metering for troubleshooting.

  4. Select Add App.

  5. Enter the required information:

    • App Name (required), e.g. Google Chrome.

    • Enabled toggle to start/stop tracking this app without deleting it.

    • Detection Rules: one or more rules that decide whether a running process should be counted. Each rule has a type and a pattern:

      • Process Name: matches the executable file name (e.g. chrome.exe).

      • Exact Path: matches the full path on disk (e.g. C:\Program Files\Google\Chrome\Application\chrome.exe).

      • Regex: matches the full path against a regular expression (e.g. (?i)chrome\.exe$). Add as many rules as you need — a process matches if any rule matches.

      Select Add Rule to add more detection rules, or select the x icon for a given rule to remove it.

  6. Select Done to save the app, then Save to apply your changes to the tenant settings.

To edit configuration for a metered app:
  1. Navigate to Insights > Intune, and select App Metering from the top menu.

  2. Select App Metering Settings.

  3. Select the App Metering Enabled button for the target tenant to enter its configuration menu.

  4. Select the Enabled button for the app to open its configuration dialog and amend its settings:

    • To temporarily disable metering for the app, toggle the Enabled switch off.

    • To change how the app is detected on target devices, add or modify Detection Rules (see above for details).

  5. Select Done to save the app, then Save to apply your changes to the tenant settings.

To permanently remove an app from App Metering:
  1. Navigate to Insights > Intune, and select App Metering from the top menu.

  2. Select App Metering Settings.

  3. Select the App Metering Enabled button for the target tenant to enter its configuration menu.

  4. Select the trashcan icon for the app to delete its configuration.

Note

If you plan to re-add the app to App Metering in the future, we recommend that you temporarily disable monitoring for it rather than deleting it.

View and interpret App Metering metrics

Once you've begun collecting metering data for an app, you can view a number of different usage metrics for it across a configurable time period.

To view metering data for an app:
  1. Navigate to Insights > Intune, and select App Metering from the top menu.

    A list of monitored apps displays, sorted by tenant.

  2. Select the app whose metrics you want to view.

  3. Use the drop-down menu to select the time period you want to report for (the default is the last 30 days).

    The main viewing pane shows the total number of devices and users for the period, and metrics for average hours spent in the app per user.

  4. Use the tabs to display usage statistics and last-used date for the app by user, by device, or by version.

  5. To export the data to your local device for further analysis, select Export as CSV.

Configure App Metering for multiple Nerdio Manager instances

You can run more than one Nerdio Manager instance against a single Entra ID and Intune tenant — for example, a production instance and a secondary instance for a separate business unit. App Metering supports this, but the two remediation scripts behave differently, so plan your target groups accordingly.

Certificate script

Collector script

Scope

One per tenant, shared by every Nerdio Manager instance. All instances use the same certificate.

One per Nerdio Manager instance. Each instance requires its own collector with a unique name.

Created by

The first Nerdio Manager instance to enable App Metering. Subsequent instances reuse it.

The primary Nerdio Manager instance, from the App Metering dialog. Each secondary instance requires a copy you create manually in Intune with its own Intune Insights URL.

Target groups

Every device group in scope for App Metering across all Nerdio Manager instances in the tenant.

Only the device groups this specific instance should meter.

Certificate script: target all in-scope groups

Because the certificate script is shared, its target groups must cover every Nerdio Manager instance that will meter devices in the tenant. In the App Metering dialog of your primary instance, set Certificate script target groups to include the device groups the primary instance uses and the device groups each secondary instance uses. If you add a secondary instance later, return to this dialog and add its groups to the certificate script assignment.

Important

Don't create additional certificate scripts, and don't rename Nerdio-SWM-Certificate. Intune Insights expects exactly this name, and a second certificate script would issue a different certificate to the same devices.

Collector script: one per instance

A single Nerdio Manager instance owns each collector script. The detection script contains the address of that instance's Intune Insights web app, and every device that runs it reports usage to that address. For this reason, you can't share a collector: a second instance needs its own copy of the collector, pointing at its own Intune Insights web app.

Troubleshooting Multi-Nerdio Manager installations

From the Nerdio Manager interface, you can only create and assign the collector script for the primary instance. To meter devices with a secondary Nerdio Manager instance, duplicate the collector remediation in Intune and change its URL as follows.

Step 1: Find the secondary instance's Intune Insights web app URL

Sign in to the secondary Nerdio Manager instance and navigate to Settings > Integrations > Intune > Intune Insights. Note the URL of the Intune Insights app service deployed for that instance, for example https://nmw-ii-app-xxxxx.azurewebsites.net.

Important

Use the address of the Intune Insights web app, not the address of the Nerdio Manager instance itself. If a web application firewall or Azure Front Door publishes the Intune Insights web app, use the address devices reach it on, not the underlying App Service address.

Step 2: Obtain the collector scripts

The collector remediation consists of two PowerShell files: a detection script, Detect-SwmEvents.ps1, which performs all of the collection work, and a remediation script, Remediate-SwmEvents.ps1, which performs no action. These are the same files Nerdio Manager uploaded for the primary instance. If you don't have a copy, contact the Nerdio Manager support team.

Step 3: Update the URL in the detection script

Open Detect-SwmEvents.ps1 in a text editor. Near the top of the file, in the Configuration section, locate the line that sets the API base URL:

$ApiBaseUrl = "https://nmw-ii-app-xxxxx.azurewebsites.net"

Replace the value with the URL of the secondary instance's Intune Insights web app from Step 1, keeping the https:// prefix and the surrounding quotation marks. Save the file. Don't make any other changes to either script.

Note

This is the only value that differs between collector scripts for different Nerdio Manager instances. The two endpoints the script calls, /device-gateway/v2/swm-rules and /device-gateway/v2/ingest, are built from this base URL. Devices must be able to reach the new address on outbound port 443.

Step 4: Create the collector remediation for the secondary instance
  1. In the Intune admin center, navigate to Devices > Scripts and remediations > Remediations and select Create.

  2. Enter a unique name that identifies the secondary instance, for example Nerdio-SWM-Collector-<secondary instance name>. Don't reuse the primary instance's collector name.

  3. Upload the edited Detect-SwmEvents.ps1 as the detection script file, and Remediate-SwmEvents.ps1 as the remediation script file.

  4. Set Run this script using the logged-on credentials to No, Enforce script signature check to No, and Run script in 64-bit PowerShell to Yes.

  5. Assign the remediation to the Entra ID device groups for the secondary Nerdio Manager instance, with a schedule of Every 12 hours.

  6. Confirm that the primary instance's Certificate script target groups includes these same device groups, so the shared certificate script also reaches them.

  7. Allow a minimum of 24 hours for devices in the secondary instance's groups to appear in that instance's App Metering tab. Offline devices take longer.

Note

Nerdio Manager only manages the scripts it created. It doesn't modify or remove a manually created collector script when you disable App Metering from the primary instance, and a manually created collector doesn't appear in the primary instance's App Metering dialog. If Nerdio publishes an updated collector script, you must update the manually created copy by hand.

For help configuring App Metering across multiple Nerdio Manager instances, contact the Nerdio Manager support team.

Disable App Metering

To disable App Metering while keeping Intune Insights enabled:

  1. Navigate to Settings > Integrations. In the Intune section, select the arrow to expand it, and navigate to Intune Insights.

  2. On the Intune tenant row, open the action menu and select App metering.

  3. Set App metering to Disabled and select Save.

Disabling Intune Insights also automatically disables App Metering.

When you disable App Metering, Nerdio Manager removes the remediation scripts and assignments it created. It leaves the following untouched:

  • A Nerdio-SWM-Certificate script that existed before you enabled App Metering from Nerdio Manager, and any assignments on it that you made outside Nerdio Manager.

  • Assignments you added to any script manually in the Intune admin center.

  • Collector scripts you duplicated manually for secondary Nerdio Manager instances.

Move from a manual App Metering configuration (from the Private Preview release)

As of its Public Preview release, App Metering is configured entirely within the Nerdio Manager interface. If you previously set up the Private Preview version of App Metering via direct configuration in the Azure portal, you can switch to native Nerdio Manager management of the feature by following the steps in Enable App Metering above.

When you perform this switch:

  • Nerdio Manager reuses your existing Nerdio-SWM-Certificate script. It keeps its existing assignments, which appear pre-selected in Certificate script target groups.

  • Nerdio Manager creates a new collector script with an instance-specific suffix. Your manually created collector remediation stays in place, so the same devices may briefly run two collectors. Once you've confirmed the new collector is Active in Intune, remove the manually created collector remediation to avoid duplicate collection.

    Important

    You can find the collector script you created during Private Preview within the Intune console, at Manage devices > Scripts and remediations. Do not delete any scripts with the author Nerdio Manager; any such scripts have been automatically created by Nerdio Manager as part of provisioning Intune functionality (including App Metering), and removing or altering these scripts may render Nerdio Manager features inoperable.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.