{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
        "slug": "dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/"
        },
        "title": "Do not use startup scores to certify first-sign-in provisioning",
        "summary": "Does the endpoint startup score measure the first sign-in or update experience being investigated?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:03+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Identify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.",
        "dse_recommendation": "Write the user’s observed delay and its stage separately from the dashboard score.",
        "primary_source": {
            "name": "Startup Performance Report in Endpoint Analytics - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Endpoint analytics uses the latest boot time for each device but excludes update phases. Its sign-in score excludes first sign-ins and sign-ins immediately after a feature update. Boot and sign-in events are retained for 29 days; a device without an uploaded event in that interval disappears from this report. These scoring rules define which experience is being compared. <a href=\"https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.</p>\n<h2>DSE recommendation</h2>\n<p>Write the user’s observed delay and its stage separately from the dashboard score. For an excluded first-sign-in scenario, arrange a controlled observation of that actual workflow instead of presenting the score as its measurement. For routine sign-in, inspect the device’s own history and the startup-process evidence before recommending a change. Keep the measured event and the business complaint linked by time and device.</p>\n<h2>Verification</h2>\n<p>Reproduce the agreed scenario on a designated test endpoint and document when the user reaches a usable desktop. Compare only applicable report events with that observation. If the device is absent, investigate event recency and upload rather than classifying absence as fast startup. Preserve the scenario, timestamps, and observed delay without claiming that a favorable aggregate certifies every provisioning experience.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Startup Performance Report in Endpoint Analytics</a>.</p>",
        "content_text": "Source facts\nEndpoint analytics uses the latest boot time for each device but excludes update phases. Its sign-in score excludes first sign-ins and sign-ins immediately after a feature update. Boot and sign-in events are retained for 29 days; a device without an uploaded event in that interval disappears from this report. These scoring rules define which experience is being compared. Microsoft Learn.\nApplicability\nIdentify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.\nDSE recommendation\nWrite the user’s observed delay and its stage separately from the dashboard score. For an excluded first-sign-in scenario, arrange a controlled observation of that actual workflow instead of presenting the score as its measurement. For routine sign-in, inspect the device’s own history and the startup-process evidence before recommending a change. Keep the measured event and the business complaint linked by time and device.\nVerification\nReproduce the agreed scenario on a designated test endpoint and document when the user reaches a usable desktop. Compare only applicable report events with that observation. If the device is absent, investigate event recency and upload rather than classifying absence as fast startup. Preserve the scenario, timestamps, and observed delay without claiming that a favorable aggregate certifies every provisioning experience.\nOfficial references\nMicrosoft Learn: Startup Performance Report in Endpoint Analytics.",
        "content_markdown": "## Source facts\n\nEndpoint analytics uses the latest boot time for each device but excludes update phases. Its sign-in score excludes first sign-ins and sign-ins immediately after a feature update. Boot and sign-in events are retained for 29 days; a device without an uploaded event in that interval disappears from this report. These scoring rules define which experience is being compared. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance).\n\n## Applicability\n\nIdentify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.\n\n## DSE recommendation\n\nWrite the user’s observed delay and its stage separately from the dashboard score. For an excluded first-sign-in scenario, arrange a controlled observation of that actual workflow instead of presenting the score as its measurement. For routine sign-in, inspect the device’s own history and the startup-process evidence before recommending a change. Keep the measured event and the business complaint linked by time and device.\n\n## Verification\n\nReproduce the agreed scenario on a designated test endpoint and document when the user reaches a usable desktop. Compare only applicable report events with that observation. If the device is absent, investigate event recency and upload rather than classifying absence as fast startup. Preserve the scenario, timestamps, and observed delay without claiming that a favorable aggregate certifies every provisioning experience.\n\n## Official references\n\n[Microsoft Learn: Startup Performance Report in Endpoint Analytics](https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not use startup scores to certify first-sign-in provisioning",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/",
                "headline": "Do not use startup scores to certify first-sign-in provisioning",
                "description": "Does the endpoint startup score measure the first sign-in or update experience being investigated?",
                "abstract": "Does the endpoint startup score measure the first sign-in or update experience being investigated?",
                "articleBody": "Source facts\nEndpoint analytics uses the latest boot time for each device but excludes update phases. Its sign-in score excludes first sign-ins and sign-ins immediately after a feature update. Boot and sign-in events are retained for 29 days; a device without an uploaded event in that interval disappears from this report. These scoring rules define which experience is being compared. Microsoft Learn.\nApplicability\nIdentify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.\nDSE recommendation\nWrite the user’s observed delay and its stage separately from the dashboard score. For an excluded first-sign-in scenario, arrange a controlled observation of that actual workflow instead of presenting the score as its measurement. For routine sign-in, inspect the device’s own history and the startup-process evidence before recommending a change. Keep the measured event and the business complaint linked by time and device.\nVerification\nReproduce the agreed scenario on a designated test endpoint and document when the user reaches a usable desktop. Compare only applicable report events with that observation. If the device is absent, investigate event recency and upload rather than classifying absence as fast startup. Preserve the scenario, timestamps, and observed delay without claiming that a favorable aggregate certifies every provisioning experience.\nOfficial references\nMicrosoft Learn: Startup Performance Report in Endpoint Analytics.",
                "datePublished": "2026-09-10T00:30:03+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not use startup scores to certify first-sign-in provisioning"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Startup Performance Report in Endpoint Analytics - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance"
                }
            }
        ]
    }
}