{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
        "slug": "dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/"
        },
        "title": "Name the device cohort before sharing endpoint analytics results",
        "summary": "Which device population is actually represented by the selected analytics scope?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:53+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 224,
        "potentially_affected": "Identify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.",
        "dse_recommendation": "Name the scope after its intended population and record the underlying tag identifier.",
        "primary_source": {
            "name": "Device Scopes - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Endpoint analytics custom device scopes filter supported reports using one scope tag. They start disabled, can need up to 24 hours after activation, and require at least ten devices. A selected scope persists across supported report pages. Deleting its underlying tag breaks the scope. The supported reports listed are startup, work-from-anywhere, application reliability, and battery health. <a href=\"https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.</p>\n<h2>DSE recommendation</h2>\n<p>Name the scope after its intended population and record the underlying tag identifier. Have the endpoint owner review membership before activating it. Include the selected scope in screenshots, exports, and discussions so an audience-specific score is not presented as the whole organization. Coordinate tag cleanup with report owners rather than treating the tag as an unused label.</p>\n<h2>Verification</h2>\n<p>After processing, compare a known included device and an excluded device with the intended population. Move between supported reports and confirm that the selected scope remains the expected one. When returning to an organization-wide review, explicitly choose All Devices and verify the change. Record processing or insufficient-data states separately from a measured poor result. Preserve the scope definition with the analysis so later readers can explain which endpoints the conclusion represents.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Device Scopes</a>.</p>",
        "content_text": "Source facts\nEndpoint analytics custom device scopes filter supported reports using one scope tag. They start disabled, can need up to 24 hours after activation, and require at least ten devices. A selected scope persists across supported report pages. Deleting its underlying tag breaks the scope. The supported reports listed are startup, work-from-anywhere, application reliability, and battery health. Microsoft Learn.\nApplicability\nIdentify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.\nDSE recommendation\nName the scope after its intended population and record the underlying tag identifier. Have the endpoint owner review membership before activating it. Include the selected scope in screenshots, exports, and discussions so an audience-specific score is not presented as the whole organization. Coordinate tag cleanup with report owners rather than treating the tag as an unused label.\nVerification\nAfter processing, compare a known included device and an excluded device with the intended population. Move between supported reports and confirm that the selected scope remains the expected one. When returning to an organization-wide review, explicitly choose All Devices and verify the change. Record processing or insufficient-data states separately from a measured poor result. Preserve the scope definition with the analysis so later readers can explain which endpoints the conclusion represents.\nOfficial references\nMicrosoft Learn: Device Scopes.",
        "content_markdown": "## Source facts\n\nEndpoint analytics custom device scopes filter supported reports using one scope tag. They start disabled, can need up to 24 hours after activation, and require at least ten devices. A selected scope persists across supported report pages. Deleting its underlying tag breaks the scope. The supported reports listed are startup, work-from-anywhere, application reliability, and battery health. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes).\n\n## Applicability\n\nIdentify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.\n\n## DSE recommendation\n\nName the scope after its intended population and record the underlying tag identifier. Have the endpoint owner review membership before activating it. Include the selected scope in screenshots, exports, and discussions so an audience-specific score is not presented as the whole organization. Coordinate tag cleanup with report owners rather than treating the tag as an unused label.\n\n## Verification\n\nAfter processing, compare a known included device and an excluded device with the intended population. Move between supported reports and confirm that the selected scope remains the expected one. When returning to an organization-wide review, explicitly choose All Devices and verify the change. Record processing or insufficient-data states separately from a measured poor result. Preserve the scope definition with the analysis so later readers can explain which endpoints the conclusion represents.\n\n## Official references\n\n[Microsoft Learn: Device Scopes](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Name the device cohort before sharing endpoint analytics results",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/",
                "headline": "Name the device cohort before sharing endpoint analytics results",
                "description": "Which device population is actually represented by the selected analytics scope?",
                "abstract": "Which device population is actually represented by the selected analytics scope?",
                "articleBody": "Source facts\nEndpoint analytics custom device scopes filter supported reports using one scope tag. They start disabled, can need up to 24 hours after activation, and require at least ten devices. A selected scope persists across supported report pages. Deleting its underlying tag breaks the scope. The supported reports listed are startup, work-from-anywhere, application reliability, and battery health. Microsoft Learn.\nApplicability\nIdentify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.\nDSE recommendation\nName the scope after its intended population and record the underlying tag identifier. Have the endpoint owner review membership before activating it. Include the selected scope in screenshots, exports, and discussions so an audience-specific score is not presented as the whole organization. Coordinate tag cleanup with report owners rather than treating the tag as an unused label.\nVerification\nAfter processing, compare a known included device and an excluded device with the intended population. Move between supported reports and confirm that the selected scope remains the expected one. When returning to an organization-wide review, explicitly choose All Devices and verify the change. Record processing or insufficient-data states separately from a measured poor result. Preserve the scope definition with the analysis so later readers can explain which endpoints the conclusion represents.\nOfficial references\nMicrosoft Learn: Device Scopes.",
                "datePublished": "2026-09-10T00:26:53+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Name the device cohort before sharing endpoint analytics results"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 224,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Device Scopes - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes"
                }
            }
        ]
    }
}