Version 69.0 July 20, 2026
Release Date: July 20, 2026
AppSource Version: 1065
Summary
Section titled “Summary”BI for Intune v69 adds visibility into device encryption and local credential recovery by introducing the new Device Recovery Key and Device Local Credential objects. These objects report whether BitLocker recovery keys and Windows LAPS local administrator credentials are backed up, how many keys are stored, and when backups and refreshes occur.
This release also enhances the Encryption Status page with new fields and filters for recovery key and local credential backup status, and adds a field to the Device object indicating whether an operating system recovery key is stored.
In addition, a new semantic model parameter allows environments affected by a Microsoft Graph issue to continue loading a limited subset of Proactive Remediation data. See the Important Notes section.
This version requires two additional Microsoft Graph permissions. See the Important Notes section.
Product Enhancements
Section titled “Product Enhancements”- Updated the Encryption Status page by adding OS Recovery Key Stored and Local Credential Stored to the main table and filter pane to improve visibility into device recovery key and local credential backup status.
- Added the ability to load Proactive Remediation data in environments where a Microsoft Graph issue would otherwise return an empty result, using the new AzureAD Proactive Remediation Assignment Enable parameter. See the Important Notes section.
New Features
Section titled “New Features”- Added new object Device Recovery Key to provide visibility into BitLocker recovery key backup status, including the number of keys stored and when they were first and last created.
- Added new object Device Local Credential to provide visibility into Windows LAPS local administrator credential backup status, including the last backup and next refresh.
Semantic Model Changes
Section titled “Semantic Model Changes”- Added field OS Recovery Key Stored to the Device object.
- Added new fields to the Device Recovery Key object: First Created Date, First Created Date (Days), Last Created Date, Last Created Date (Days), Recovery Key Count, Recovery Key Stored, Volume Type.
- Added new fields to the Device Local Credential object: Last Backup, Last Backup (Days), Local Credential Stored, Next Refresh, Next Refresh (Days).
- Added new parameter AzureAD Proactive Remediation Assignment Enable to the semantic model (Default: True). This parameter controls whether Proactive Remediation assignment details are collected during sync. In environments affected by a Microsoft Graph issue, set it to False to allow the remaining Proactive Remediation data to load. See the Important Notes section.
Important Notes
Section titled “Important Notes”- [Action Required] This version requires two additional permissions on the app registration in Microsoft Entra ID. Add BitlockerKey.ReadBasic.All and DeviceLocalCredential.ReadBasic.All. Without these permissions, the new recovery key and local credential data will not be reported. See Entra App Permissions.
- If BitlockerKey.ReadBasic.All is not granted, the OS Recovery Key Stored field on the Encryption Status page displays False for all records, even on devices that have a recovery key backed up.
- In some environments, Microsoft Graph returns a 503 error when BI for Intune requests Proactive Remediation assignment details, which causes the related data to return empty. This is a defect in the Microsoft API, not in BI for Intune, and PowerStacks has been working with Microsoft to have it corrected for more than a year. In an affected environment, it is not possible to retrieve the detailed deployment information for proactive remediations. To allow the rest of the Proactive Remediation data to load, set the AzureAD Proactive Remediation Assignment Enable parameter to False so that BI for Intune does not request the assignment details that trigger the error. If you would like to pursue a correction, PowerStacks can help you gather evidence of the Microsoft issue so you can open a support case with Microsoft. Contact support@powerstacks.com.
- Always back up your custom reports before upgrading.