Inventory & device details
Read device identity, enrollment, encryption, and check-in state without losing the context behind each field.
On this page
The inventory is the starting point for a device investigation. Open Device management and select View device for a native managed device. Check the workspace and the provider connection before interpreting the list.
Read the inventory
| Field | How to use it |
|---|---|
| Device | The provider-reported name and OS version; use the stable device identity when binding a response channel |
| Enrollment | Whether management enrollment is reported by the engine, rather than simply whether an inventory record exists |
| Encryption | The provider's current report; an unknown state is not evidence of encryption or decryption |
| Last seen | The last reported check-in in UTC; stale values can indicate an offline machine or reporting delay |
| Manage | Open details and see the actions available for this device and your role |
Native inventory is paginated in batches of up to 100 records. Counts such as Devices on this page refer to that page, not your entire organization. Use Next page when available and the provider console for a complete fleet view. Profile listings may also be truncated at 100.
Inspect a device
- Confirm its provider identity and platform match the endpoint you intend to investigate.
- Review enrollment and recent check-in information.
- Inspect profile delivery and any available action history.
- Check whether remote actions use the Fleet provider path or a separately provisioned Beam response binding.
- If an action is missing, check role, platform support, connection settings, and deployment enablement before treating it as an error.
Do not use a hostname as proof of identity. A response binding pins the Fleet host ID, inventory UUID, platform, and device-channel identity. Replacing hardware requires a new verified binding.
Interpret incomplete information
Intune inventory is fetched live and stops after ten provider pages. Beam marks partial results; filters and counts describe only the returned records. Unsupported platforms are omitted. Native and Intune values are provider reports, not an independent attestation of endpoint security.
An encryption boolean does not mean Beam has escrowed a FileVault or BitLocker recovery key. Recovery-key escrow UI is not available. Use your provider's recovery process and protect the underlying identity keys.
Verify after a change
After enrollment or a profile operation, refresh inventory and check the device itself. A successful provider request can precede its next check-in. Use operation history to distinguish acceptance from device completion and avoid retrying an uncertain destructive action.