Endpoint Analytics Remediation Scripts
A community-driven repository of 86+ PowerShell detection and remediation scripts for Microsoft Intune Endpoint Analytics. Includes scripts for system health, security hardening, device management, application management, optimization, and diagnostics.
Security Analysis
50 files scanned on Jan 8, 2026
The collection contains several legitimate admin/remediation tasks, but with notable security concerns: (1) data-loss risk from clearing Downloads, (2) destructive OS-component removal, (3) potential persistence/privilege-change risk via a Local Admin remediation, (4) risky use of Win32_Product for software detection, and (5) configuration hazards from hardcoded placeholders and registry policy changes. No obfuscated code, credential harvesting, or external data exfiltration detected.
Swipe to see more
You might also like
Intune Remediations
A collection of PowerShell detection and remediation scripts for Microsoft Intune. Organized into categories: Device Compliance, Device Configuration, Device Performance, Microsoft Defender AV, Miscellaneous, Reporting, and Toast Notifications for proactive endpoint issue resolution.
Get-IntuneManagementExtensionDiagnostics
A PowerShell script for analyzing Intune Management Extension logs and creating timeline reports. Tracks Win32App deployments, WinGetApp packages, PowerShell scripts, Proactive Remediations, Custom Compliance, and Autopilot ESP phases with HTML reports and integrated LogViewerUI.
Get-AutopilotDiagnosticsCommunity
A PowerShell diagnostic script for analyzing Windows Autopilot deployments. Provides comprehensive details about Autopilot profile settings, policies, apps, and certificate profiles tracked via Enrollment Status Page, with support for local PC analysis and captured log files.
Intune Device Details GUI
A PowerShell-based GUI tool for visualizing comprehensive Intune device information. Shows Azure AD group memberships, Intune filter assignments, application and configuration targeting, BitLocker recovery keys, LAPS passwords, Autopilot profiles, and remediation script status with color-coded assignment states.
