{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
        "slug": "dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/"
        },
        "title": "Preserve Update Manager evidence before its query windows expire",
        "summary": "Plan evidence retrieval around the separate assessment and installation history windows in Azure Resource Graph.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:53+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 219,
        "potentially_affected": "Reports and evidence exports using Azure Update Manager operations data in Azure Resource Graph.",
        "dse_recommendation": "Set an evidence-export cadence that fits both history windows and keep assessment records separate from installation results.",
        "primary_source": {
            "name": "Query Resources with Azure Resource Graph in Azure Update Manager | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/update-manager/query-logs",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s Update Manager guidance specifies seven days of recent assessment history and 30 days of installation history available through Resource Graph. These are different windows; a report should not assume the longer installation window also covers assessments.</p>\n<p>The documented assessment records distinguish an operation-level summary from individual available software updates. Installation records likewise distinguish the run summary from individual update results. <a href=\"https://learn.microsoft.com/en-us/azure/update-manager/query-logs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the report&#8217;s required period, machine population, record types, and evidence owner. Separate a current assessment question from proof of an earlier installation; absence outside the query window should remain an evidence limitation.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends exporting the required results before the shorter relevant window closes and retaining them under the organization&#8217;s approved evidence policy. Preserve machine identity, operation identity, record type, and timestamps so later reviewers can reconnect summary and per-update evidence. Make a missed export visible rather than filling the historical gap with current state.</p>\n<h2>Verification</h2>\n<p>Test retrieval for known assessment and installation operations, comparing summary rows with their per-update records. Check the report&#8217;s date boundaries and confirm an intentionally out-of-window query is labeled appropriately. Verify that the retained export remains readable and attributable after the live query no longer supplies the original records.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/update-manager/query-logs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Query Resources with Azure Resource Graph in Azure Update Manager</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s Update Manager guidance specifies seven days of recent assessment history and 30 days of installation history available through Resource Graph. These are different windows; a report should not assume the longer installation window also covers assessments.\nThe documented assessment records distinguish an operation-level summary from individual available software updates. Installation records likewise distinguish the run summary from individual update results. Microsoft Learn.\nApplicability\nIdentify the report’s required period, machine population, record types, and evidence owner. Separate a current assessment question from proof of an earlier installation; absence outside the query window should remain an evidence limitation.\nDSE recommendation\nDSE recommends exporting the required results before the shorter relevant window closes and retaining them under the organization’s approved evidence policy. Preserve machine identity, operation identity, record type, and timestamps so later reviewers can reconnect summary and per-update evidence. Make a missed export visible rather than filling the historical gap with current state.\nVerification\nTest retrieval for known assessment and installation operations, comparing summary rows with their per-update records. Check the report’s date boundaries and confirm an intentionally out-of-window query is labeled appropriately. Verify that the retained export remains readable and attributable after the live query no longer supplies the original records.\nOfficial references\nMicrosoft Learn: Query Resources with Azure Resource Graph in Azure Update Manager. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s Update Manager guidance specifies seven days of recent assessment history and 30 days of installation history available through Resource Graph. These are different windows; a report should not assume the longer installation window also covers assessments.\n\nThe documented assessment records distinguish an operation-level summary from individual available software updates. Installation records likewise distinguish the run summary from individual update results. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/update-manager/query-logs).\n\n## Applicability\n\nIdentify the report’s required period, machine population, record types, and evidence owner. Separate a current assessment question from proof of an earlier installation; absence outside the query window should remain an evidence limitation.\n\n## DSE recommendation\n\nDSE recommends exporting the required results before the shorter relevant window closes and retaining them under the organization’s approved evidence policy. Preserve machine identity, operation identity, record type, and timestamps so later reviewers can reconnect summary and per-update evidence. Make a missed export visible rather than filling the historical gap with current state.\n\n## Verification\n\nTest retrieval for known assessment and installation operations, comparing summary rows with their per-update records. Check the report’s date boundaries and confirm an intentionally out-of-window query is labeled appropriately. Verify that the retained export remains readable and attributable after the live query no longer supplies the original records.\n\n## Official references\n\n[Microsoft Learn: Query Resources with Azure Resource Graph in Azure Update Manager](https://learn.microsoft.com/en-us/azure/update-manager/query-logs). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve Update Manager evidence before its query windows expire",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/",
                "headline": "Preserve Update Manager evidence before its query windows expire",
                "description": "Plan evidence retrieval around the separate assessment and installation history windows in Azure Resource Graph.",
                "abstract": "Plan evidence retrieval around the separate assessment and installation history windows in Azure Resource Graph.",
                "articleBody": "Source facts\nMicrosoft’s Update Manager guidance specifies seven days of recent assessment history and 30 days of installation history available through Resource Graph. These are different windows; a report should not assume the longer installation window also covers assessments.\nThe documented assessment records distinguish an operation-level summary from individual available software updates. Installation records likewise distinguish the run summary from individual update results. Microsoft Learn.\nApplicability\nIdentify the report’s required period, machine population, record types, and evidence owner. Separate a current assessment question from proof of an earlier installation; absence outside the query window should remain an evidence limitation.\nDSE recommendation\nDSE recommends exporting the required results before the shorter relevant window closes and retaining them under the organization’s approved evidence policy. Preserve machine identity, operation identity, record type, and timestamps so later reviewers can reconnect summary and per-update evidence. Make a missed export visible rather than filling the historical gap with current state.\nVerification\nTest retrieval for known assessment and installation operations, comparing summary rows with their per-update records. Check the report’s date boundaries and confirm an intentionally out-of-window query is labeled appropriately. Verify that the retained export remains readable and attributable after the live query no longer supplies the original records.\nOfficial references\nMicrosoft Learn: Query Resources with Azure Resource Graph in Azure Update Manager. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:28:53+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve Update Manager evidence before its query windows expire"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 219,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Query Resources with Azure Resource Graph in Azure Update Manager | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/update-manager/query-logs"
                }
            }
        ]
    }
}