Pro

Find who's using any workstation and their email in 2 seconds.

The reverse lookup of Get Primary Device And Email From User. Find the assigned user from a device name, with their email address from Active Directory. Returns user UPN, mail, AD attributes, and last sign-in.

Included in the Pro tier · 14-day trial, no card

Get Primary User And Email From Device

The problem

An alert fires: "WS-12345 hasn't checked in for 90 days". You need to contact the owner. Or a security incident requires immediate identification of the assigned user.

  • SCCM WQLSMS_UserMachineRelationship reverse-query, then resolve the SamAccountName.
  • AD lookupfetch mail, department, manager — three more attribute queries.
  • Entra correlationcheck Entra last sign-in to confirm the assignment is current.

Three minutes per device without this tool. 2 seconds with it. Bulk-process 500 devices in under a minute.

The TontonTools way

Get Primary User And Email From Device is the bidirectional twin of Get Primary Device And Email From User — same UX, opposite direction.

  • Single device modetype a device name, get UPN + mail + manager + department + Entra last sign-in.
  • Bulk modepaste 500 devices, get 500 owners in one grid — ready for the comms tool.
  • Full identity contextmail, manager mail, AD department, Entra last sign-in returned in every row.
  • CSV exportpipe directly into mail merge or your incident-response comms workflow.

Key features

Built for high-stakes operations where forgetting a system is not an option.

  • Reverse primary-user lookup

    Type a device, get the assigned user. SCCM SMS_UserMachineRelationship + Entra registered owner correlated.

  • Bulk mode up to 10,000 devices

    CSV, paste or SCCM device collection. Single-pass bulk grid with sortable columns.

  • Mail + manager mail in every row

    Full identity context resolved from AD: UPN, mail, manager mail, department, title. Copy-paste ready for comms.

  • Shared-device awareness

    Kiosks and conference-room machines surface naturally — multiple primary users or none, which is the correct signal for those scenarios.

  • Entra last sign-in

    Confirm whether the assignment is current. Stale assignments are flagged before you send the wrong notification.

  • CSV export

    Result grid exports to CSV in one click — ready for mail merge, incident comms, or audit attachment.

See it in action

Real screens. No marketing renders.

  • Import a device list and resolve the primary user, AD email and display name for every machine.
  • Paste device names; get the instant single-device answer, including no-affinity and not-found cases.
  • Or pull straight from any SCCM device collection — search, pick, and resolve every member at once.
  • A timestamped log traces every WMI lookup — resource name to user to resolved email, line by line.

Technical details

What runs where. What it writes to disk. What permissions it needs.

Authentication

SCCM — current user credentials (Kerberos)

Microsoft Graph — Client Secret or Certificate (JWT Client Assertion)

Systems

Microsoft Configuration Manager (SCCM / MECM)

Active Directory (on-prem)

Microsoft Entra ID

Bulk limit

10,000 devices per operation

Who it's for

Security teams responding to alerts. Asset managers preparing decommissioning notices. L2 engineers investigating compliance violations. Anyone who needs to put a human face on a device name — fast.

Identify a device's owner instantly.

Try Get Primary User And Email From Device — included in Pro and Enterprise tiers.