Recent Releases
The 6 most recent releases are listed below. For older versions, see the release archive.
Version 69.0 July 20, 2026
Section titled Version 69.0 July 20, 2026Release Date: July 20, 2026
AppSource Version: 1065
Summary
Section titled “Summary”BI for Intune v69 adds visibility into device encryption and local credential recovery by introducing the new Device Recovery Key and Device Local Credential objects. These objects report whether BitLocker recovery keys and Windows LAPS local administrator credentials are backed up, how many keys are stored, and when backups and refreshes occur.
This release also enhances the Encryption Status page with new fields and filters for recovery key and local credential backup status, and adds a field to the Device object indicating whether an operating system recovery key is stored.
In addition, a new semantic model parameter allows environments affected by a Microsoft Graph issue to continue loading a limited subset of Proactive Remediation data. See the Important Notes section.
This version requires two additional Microsoft Graph permissions. See the Important Notes section.
Product Enhancements
Section titled “Product Enhancements”- Updated the Encryption Status page by adding OS Recovery Key Stored and Local Credential Stored to the main table and filter pane to improve visibility into device recovery key and local credential backup status.
- Added the ability to load Proactive Remediation data in environments where a Microsoft Graph issue would otherwise return an empty result, using the new AzureAD Proactive Remediation Assignment Enable parameter. See the Important Notes section.
New Features
Section titled “New Features”- Added new object Device Recovery Key to provide visibility into BitLocker recovery key backup status, including the number of keys stored and when they were first and last created.
- Added new object Device Local Credential to provide visibility into Windows LAPS local administrator credential backup status, including the last backup and next refresh.
Semantic Model Changes
Section titled “Semantic Model Changes”- Added field OS Recovery Key Stored to the Device object.
- Added new fields to the Device Recovery Key object: First Created Date, First Created Date (Days), Last Created Date, Last Created Date (Days), Recovery Key Count, Recovery Key Stored, Volume Type.
- Added new fields to the Device Local Credential object: Last Backup, Last Backup (Days), Local Credential Stored, Next Refresh, Next Refresh (Days).
- Added new parameter AzureAD Proactive Remediation Assignment Enable to the semantic model (Default: True). This parameter controls whether Proactive Remediation assignment details are collected during sync. In environments affected by a Microsoft Graph issue, set it to False to allow the remaining Proactive Remediation data to load. See the Important Notes section.
Important Notes
Section titled “Important Notes”- [Action Required] This version requires two additional permissions on the app registration in Microsoft Entra ID. Add BitlockerKey.ReadBasic.All and DeviceLocalCredential.ReadBasic.All. Without these permissions, the new recovery key and local credential data will not be reported. See Entra App Permissions.
- If BitlockerKey.ReadBasic.All is not granted, the OS Recovery Key Stored field on the Encryption Status page displays False for all records, even on devices that have a recovery key backed up.
- In some environments, Microsoft Graph returns a 503 error when BI for Intune requests Proactive Remediation assignment details, which causes the related data to return empty. This is a defect in the Microsoft API, not in BI for Intune, and PowerStacks has been working with Microsoft to have it corrected for more than a year. In an affected environment, it is not possible to retrieve the detailed deployment information for proactive remediations. To allow the rest of the Proactive Remediation data to load, set the AzureAD Proactive Remediation Assignment Enable parameter to False so that BI for Intune does not request the assignment details that trigger the error. If you would like to pursue a correction, PowerStacks can help you gather evidence of the Microsoft issue so you can open a support case with Microsoft. Contact support@powerstacks.com.
- Always back up your custom reports before upgrading.
Version 68.0 June 17, 2026
Section titled Version 68.0 June 17, 2026Release Date: June 17, 2026
AppSource Version: 1061
Summary
Section titled “Summary”BI for Intune v68 is a maintenance release that resolves a timeout issue introduced in v67 affecting App Deployment and Driver Updates data collection.
Bug Fixes
Section titled “Bug Fixes”- Resolved a timeout issue introduced in v67 that could cause App Deployment and Driver Updates data collection to time out during sync.
Version 67.0 June 7, 2026
Section titled Version 67.0 June 7, 2026Release Date: June 7, 2026
AppSource Version: 1059
Summary
Section titled “Summary”BI for Intune v67 expands compliance reporting capabilities by introducing a relationship between Compliance Policy and Compliance Policy Setting data. This enhancement makes it easier to understand which settings are configured within a specific compliance policy and provides additional context when reviewing compliance configurations.
This release also enhances the Device Compliance and Device Compliance Settings pages with Policy Name filtering and drill-through capabilities, making it easier to analyze policy-specific compliance data.
In addition, compliance reporting data has been migrated to the Microsoft Export API and new semantic model parameters have been added to provide greater control over synchronization behavior and Compliance Policy State data collection.
Product Enhancements
Section titled “Product Enhancements”- Migrated Compliance Policy State and Compliance Policy Setting State data collection to the Microsoft Intune Export API to improve reliability and support larger datasets.
- Added a new relationship between the Compliance Policy and Compliance Policy Setting objects, allowing compliance settings to be viewed in the context of the policy that configured them.
- Updated the Device Compliance Settings page by adding Policy Name to the main table, filter pane, and drill-through pane.
- Updated the Device Compliance page by adding Policy Name to the drill-through pane.
Semantic Model Changes
Section titled “Semantic Model Changes”- Renamed semantic model parameter AzureAD Export URL Wait (s) to AzureAD Export URL Post Wait (s) (Default: 1 second). See the Important Notes section.
- Added new parameter AzureAD Export URL Get Wait (s) to the semantic model (Default: 1 second). This parameter controls the delay between Export API status checks during sync.
- Added new parameter AzureAD Compliance Policy State Enable to the semantic model (Default: True). This parameter controls whether Compliance Policy State data is collected during sync.
Important Notes
Section titled “Important Notes”- Renamed semantic model parameter AzureAD Export URL Wait (s) to AzureAD Export URL Post Wait (s). This is a breaking change. Custom reports, documentation, or automation referencing the previous parameter name must be updated.
- Always back up your custom reports before upgrading.
Version 66.0 May 10, 2026
Section titled Version 66.0 May 10, 2026Release Date: May 10, 2026 AppSource Version: 1058
Summary
Section titled “Summary”BI for Intune v66 hardens the application deployment status sync against a Microsoft Intune Export API edge case. When the DeviceInstallStatusByApp export occasionally completed with a null export URL, sync jobs would fail mid-run. The new validation logic catches the null URL case and the updated handling clears the error message customers were seeing (Microsoft.Data.Mashup.ErrorCode = 10277).
If you’ve seen intermittent sync failures on application deployment data, this release resolves them.
Product Enhancements
Section titled “Product Enhancements”- Updated handling for the Microsoft Intune Export API DeviceInstallStatusByApp endpoint to address intermittent synchronization failures caused by incomplete API responses.
Bug Fixes
Section titled “Bug Fixes”- Fixed an issue that could cause synchronization failures with the following error message:
We cannot convert the value null to type Text.. Microsoft.Data.Mashup.ErrorCode = 10277 - Resolved a condition where the Microsoft Intune Export API returned a status of Completed while the export URL value was unexpectedly returned as null.
- Added additional validation logic to ensure a valid export URL is present before processing completed export jobs.
Semantic Model Changes
Section titled “Semantic Model Changes”- N/A
Important Notes
Section titled “Important Notes”- This issue was caused by unexpected behavior from a Microsoft Intune API response associated with application deployment status exports.
- Customers experiencing intermittent synchronization failures related to application deployment status data should update to this release as soon as possible.
- Always back up your custom reports before upgrading.
Version 65.0 Feb. 21, 2026
Section titled Version 65.0 Feb. 21, 2026Release Date: February 21, 2026 AppSource Version: 1057
Summary
Section titled “Summary”BI for Intune v65 introduces expanded authentication reporting capabilities. This release adds the new User Sign-Ins Auth Details object, providing deeper visibility into authentication methods, requirements, and outcomes.
These enhancements support improved investigation and reporting of user sign-in activity across your environment.
New Features
Section titled “New Features”- Added new object User Sign-Ins Auth Details to provide expanded visibility into authentication activity and sign-in requirements.
Semantic Model Changes
Section titled “Semantic Model Changes”- Added new fields to the User Sign-Ins Auth Details object: Authentication Date, Authentication Date (Days), Authentication Method, Authentication Method Detail, Requirement, Result Detail, Succeeded.
Important Notes
Section titled “Important Notes”- Always back up your custom reports before upgrading.
Version 64.0 Feb. 15, 2026
Section titled Version 64.0 Feb. 15, 2026Release Date: February 15, 2026 AppSource Version: 1056
Summary
Section titled “Summary”BI for Intune v64 introduces expanded Microsoft Defender for Endpoint and Microsoft Entra ID risk visibility. This release adds the new User Risk object and Risky Users page, providing insight into user risk posture and sign-in risk state. It also enhances Windows Protection reporting with additional onboarding and sensor status fields.
Improved sync reliability and updated policy reporting ensure more accurate visibility across devices and users.
This release requires a new Microsoft Graph permission for user-risk reporting; see Important Notes.
Product Enhancements
Section titled “Product Enhancements”- Updated the Configuration Policy data to ensure all policy types are properly displayed, including Elevation settings policy and Local user group membership.
- Updated the Windows Protection data source for improved reliability and completeness.
- Added new fields to the Device Info page: OS Quality Update Version, OS Quality Update Release Date, and OS Quality Update Type to improve visibility into Windows servicing status.
- Updated the Windows Protection page filters by removing Filter by ATP Status and adding Filter by MDE Onboarding Status.
- Added new fields to the User object: Last Interactive Sign-In, Last Interactive Sign-In (Days), Last Non-Interactive Sign-In, Last Non-Interactive Sign-In (Days), Last Successful Sign-In, Last Successful Sign-In (Days).
- Updated the Group object to include Distribution as a supported Group Type.
- Added Risk State and Risk Level to the Sign-Ins page main table and added related filters to improve visibility into sign-in risk posture.
New Features
Section titled “New Features”- Added new object User Risk to provide visibility into user risk posture and remediation status.
- Added new page Risky Users to support reporting on Microsoft Entra ID risky users.
Bug Fixes
Section titled “Bug Fixes”- Resolved an issue where some Configuration Policy types were not appearing in reports.
Semantic Model Changes
Section titled “Semantic Model Changes”- Removed object Windows Defender ATP and associated fields: ATP Compliant, ATP Conflict, ATP Error, ATP Non Compliant, ATP Not Applicable, ATP Not Assigned, ATP Remediated, ATP State, ATP Status, ATP Unknown.
- Added new fields to the Windows Protection object: Critical Failure, MDE Can Be Onboarded, MDE Failed, MDE Insufficient Info, MDE Not Onboarded, MDE Onboarded, MDE Onboarding Status, MDE Sensor State, MDE Unsupported, Pending Full Scan, Pending Manual Steps, Pending Offline Scan, Pending Reboot, Tamper Protection Enabled.
- Added new object User Risk with fields: Risk Lasted Updated, Risk Lasted Updated (Days), User Risk Count, User Risk Level, User Risk Level Hidden, User Risk Level High, User Risk Level Low, User Risk Level Medium, User Risk Level None, User Risk Level Unknown Future Value, User Risk State, User Risk State At Risk, User Risk State Confirmed Compromised, User Risk State Confirmed Safe, User Risk State Dismissed, User Risk State None, User Risk State Remediated, User Risk State Unknown Future Value.
- Added new fields to the User Sign-Ins object: Sign-In Risk Level, Sign-In Risk Level Hidden, Sign-In Risk Level High, Sign-In Risk Level Low, Sign-In Risk Level Medium, Sign-In Risk Level None, Sign-In Risk Level Unknown Future Value, Sign-In Risk State, Sign-In Risk State At Risk, Sign-In Risk State Confirmed Compromised, Sign-In Risk State Confirmed Safe, Sign-In Risk State Dismissed, Sign-In Risk State None, Sign-In Risk State Remediated, Sign-In Risk State Unknown Future State.
Important Notes
Section titled “Important Notes”- [Action Required] This version requires an additional Microsoft Graph permission to be added to the app registration in Microsoft Entra ID. Please add IdentityRiskyUser.Read.All. Without this permission, the Risky Users page and related sync processes will not populate properly. Update your installation documentation to include this permission.
- Removed the Windows Defender ATP object. Custom reports referencing ATP fields must be updated to use Windows Protection fields.
- Microsoft Graph API instability (HTTP 503 / 504) continues to affect some tenants intermittently. The new AzureAD Application Assignment Enable parameter provides a temporary workaround. Please contact us if you have this issue — additional support cases opened with Microsoft will help prioritize a fix.
- Always back up your custom reports before upgrading.