Skip to content

2026

Who's running Ollama on your fleet? A read-only shadow-AI inventory

Cover: read-only shadow-AI inventory flagging unsanctioned local AI tools and leavers

Somewhere on your fleet right now, someone has quietly installed a local LLM. Maybe it's Ollama pulling a model, maybe LM Studio, maybe a coding assistant quietly indexing your repos into a local model that sits on the laptop — and never gets wiped when they leave. Intune won't tell you — it doesn't inventory "AI tools" as a thing. This is a scheduled, read-only collector that turns shadow AI into a governance report: who's running what, sanctioned or not, and the finding that should worry you most — leavers who still have it installed.

Documentation that writes itself: a read-only snapshot of your whole Intune config

Cover: read-only Intune and Windows 365 configuration documented automatically

Ask an admin for "the documentation" of their Intune tenant and you'll get a nervous laugh. It's in the portal — spread across compliance policies, configuration profiles, app assignments, Autopilot profiles, update rings — and the moment anyone writes it down in a Word doc, it's out of date. This is a scheduled, read-only collector that renders the entire Intune and Windows 365 configuration into one always-current, human-readable document.

One row per device: building the inventory Intune won't hand you

Cover: joining scattered Intune, Entra, warranty and Defender data into one device inventory row

Every fleet question starts the same way — how many devices, running what, owned by whom, and where do they sit? Intune knows all of it. The problem is it knows each part in a different place: the OS on the device blade, the user's country in Entra, the warranty in a Notes field, the Defender agent in a security report. This is the read-only collector that joins them into one flat row per device you can actually slice.