{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-033-control-when-a-system-insights-capability-runs/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
        "slug": "dse-20260908-033-control-when-a-system-insights-capability-runs",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-033-control-when-a-system-insights-capability-runs/"
        },
        "title": "Control when a System Insights capability runs",
        "summary": "How should capability enablement and prediction scheduling be changed in System Insights?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:38+00:00",
        "modified_at": "2026-09-08T18:17:14+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 213,
        "potentially_affected": "Use this review when configuring an existing System Insights capability.",
        "dse_recommendation": "Have the server owner choose the desired run window and explain any decision to disable the capability.",
        "primary_source": {
            "name": "Manage System Insights capabilities in Windows Admin Center",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Disabling a System Insights capability prevents invocation; for nondefault capabilities it also stops their data collection. Invoking a capability runs it immediately, and Microsoft suggests scheduling predictions outside business hours to avoid conflict with critical operations. The documented PowerShell interface supports a separate custom schedule for each capability. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when configuring an existing System Insights capability. Identify whether it is a default or added capability, its present state, its schedule, and the business operation that should not be disturbed.</p>\n<h2>DSE recommendation</h2>\n<p>Have the server owner choose the desired run window and explain any decision to disable the capability. Record the difference between an immediate test run and an ongoing schedule change. Consider the data-collection consequence for a nondefault capability before disabling it. Preserve the original state and schedule so the agreed configuration can be restored if needed.</p>\n<h2>Verification</h2>\n<p>Inspect the capability state and schedule after the approved change. Observe a scheduled execution at the intended time and record its completion result. Check that an immediate invocation was not mistaken for proof of the recurring schedule. Retain the configuration with the owner&#8217;s review date and investigate unexpected runs before changing additional capabilities.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage System Insights capabilities in Windows Admin Center</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nDisabling a System Insights capability prevents invocation; for nondefault capabilities it also stops their data collection. Invoking a capability runs it immediately, and Microsoft suggests scheduling predictions outside business hours to avoid conflict with critical operations. The documented PowerShell interface supports a separate custom schedule for each capability. Microsoft documentation.\nApplicability\nUse this review when configuring an existing System Insights capability. Identify whether it is a default or added capability, its present state, its schedule, and the business operation that should not be disturbed.\nDSE recommendation\nHave the server owner choose the desired run window and explain any decision to disable the capability. Record the difference between an immediate test run and an ongoing schedule change. Consider the data-collection consequence for a nondefault capability before disabling it. Preserve the original state and schedule so the agreed configuration can be restored if needed.\nVerification\nInspect the capability state and schedule after the approved change. Observe a scheduled execution at the intended time and record its completion result. Check that an immediate invocation was not mistaken for proof of the recurring schedule. Retain the configuration with the owner’s review date and investigate unexpected runs before changing additional capabilities.\nOfficial references\nMicrosoft Learn: Manage System Insights capabilities in Windows Admin Center. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nDisabling a System Insights capability prevents invocation; for nondefault capabilities it also stops their data collection. Invoking a capability runs it immediately, and Microsoft suggests scheduling predictions outside business hours to avoid conflict with critical operations. The documented PowerShell interface supports a separate custom schedule for each capability. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities).\n\n## Applicability\n\nUse this review when configuring an existing System Insights capability. Identify whether it is a default or added capability, its present state, its schedule, and the business operation that should not be disturbed.\n\n## DSE recommendation\n\nHave the server owner choose the desired run window and explain any decision to disable the capability. Record the difference between an immediate test run and an ongoing schedule change. Consider the data-collection consequence for a nondefault capability before disabling it. Preserve the original state and schedule so the agreed configuration can be restored if needed.\n\n## Verification\n\nInspect the capability state and schedule after the approved change. Observe a scheduled execution at the intended time and record its completion result. Check that an immediate invocation was not mistaken for proof of the recurring schedule. Retain the configuration with the owner’s review date and investigate unexpected runs before changing additional capabilities.\n\n## Official references\n\n[Microsoft Learn: Manage System Insights capabilities in Windows Admin Center](https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Control when a System Insights capability runs",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/",
                "headline": "Control when a System Insights capability runs",
                "description": "How should capability enablement and prediction scheduling be changed in System Insights?",
                "abstract": "How should capability enablement and prediction scheduling be changed in System Insights?",
                "articleBody": "Source facts\nDisabling a System Insights capability prevents invocation; for nondefault capabilities it also stops their data collection. Invoking a capability runs it immediately, and Microsoft suggests scheduling predictions outside business hours to avoid conflict with critical operations. The documented PowerShell interface supports a separate custom schedule for each capability. Microsoft documentation.\nApplicability\nUse this review when configuring an existing System Insights capability. Identify whether it is a default or added capability, its present state, its schedule, and the business operation that should not be disturbed.\nDSE recommendation\nHave the server owner choose the desired run window and explain any decision to disable the capability. Record the difference between an immediate test run and an ongoing schedule change. Consider the data-collection consequence for a nondefault capability before disabling it. Preserve the original state and schedule so the agreed configuration can be restored if needed.\nVerification\nInspect the capability state and schedule after the approved change. Observe a scheduled execution at the intended time and record its completion result. Check that an immediate invocation was not mistaken for proof of the recurring schedule. Retain the configuration with the owner’s review date and investigate unexpected runs before changing additional capabilities.\nOfficial references\nMicrosoft Learn: Manage System Insights capabilities in Windows Admin Center. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:38+00:00",
                "dateModified": "2026-09-08T18:17:14+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-033-control-when-a-system-insights-capability-runs/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Control when a System Insights capability runs"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 213,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage System Insights capabilities in Windows Admin Center",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/system-insights/managing-capabilities"
                }
            }
        ]
    }
}