Public/Get-IntuneChangeTimeline.ps1

function Get-IntuneChangeTimeline {
    <#
    .SYNOPSIS
    Shows what changed in Intune and what happened on devices afterwards, in one timeline.
    .DESCRIPTION
    Merges Intune audit events (who changed what, when), configuration differences between two local
    snapshots, and changes in reported device results. Check-in and inventory refreshes are counted
    but not listed. When a device reports a failure on the same workload soon after a change, the
    change is marked as correlated in time. Correlation is not proof of cause. Read only.
    .PARAMETER ReferenceSnapshotPath
    Earlier local snapshot. Use with DifferenceSnapshotPath for an offline comparison.
    .PARAMETER DifferenceSnapshotPath
    Later local snapshot.
    .PARAMETER CorrelationHours
    How long after a change a reported failure on the same workload is marked as correlated. Default 72.
    .EXAMPLE
    Get-IntuneChangeTimeline
    .EXAMPLE
    (Get-IntuneChangeTimeline -ReferenceSnapshotPath .\monday.json -DifferenceSnapshotPath .\tuesday.json).Entries |
        Format-Table Time, Kind, Title, Target, Actor
    #>

    [CmdletBinding(DefaultParameterSetName = 'Live')]
    param(
        [Parameter(Mandatory, ParameterSetName = 'Snapshot')] [ValidateNotNullOrEmpty()] [string] $ReferenceSnapshotPath,
        [Parameter(Mandatory, ParameterSetName = 'Snapshot')] [ValidateNotNullOrEmpty()] [string] $DifferenceSnapshotPath,
        [ValidateRange(1, 720)] [int] $CorrelationHours = 72
    )

    if ($PSCmdlet.ParameterSetName -eq 'Snapshot') {
        $comparison = Compare-IntuneAccessSnapshot -ReferencePath $ReferenceSnapshotPath -DifferencePath $DifferenceSnapshotPath
        $current = Read-IntuneAccessSnapshotFile -Path $DifferenceSnapshotPath
        return Get-IntuneAccessChangeTimeline -AuditEvent @(Get-IntuneAccessProperty $current.Data 'AuditEvents' @()) -SnapshotComparison $comparison -DeploymentOutcome @(Get-IntuneAccessProperty $current.Data 'DeploymentOutcomes' @()) -Workload @(Get-IntuneAccessProperty $current.Data 'WorkloadObjects' @()) -AsOf ([DateTimeOffset] $comparison.DifferenceAt) -CorrelationHours $CorrelationHours
    }

    $collection = Get-IntuneAccessInsightCollection -IncludeOperationalEvidence -IncludeAuditEvidence
    Get-IntuneAccessChangeTimeline -AuditEvent @($collection.AuditEvents) -DeploymentOutcome @($collection.DeploymentOutcomes) -Workload @($collection.WorkloadObjects) -CorrelationHours $CorrelationHours
}