{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
        "slug": "dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/"
        },
        "title": "Separate service and client evidence in Intune feature-update reports",
        "summary": "Why can a feature-update report show an offer state before detailed device installation progress appears?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:48+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 200,
        "potentially_affected": "Use this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.",
        "dse_recommendation": "Keep service-offer processing and client-installation observations separate in the support record.",
        "primary_source": {
            "name": "Reports for Windows Feature Update Policies - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune feature-update reports combine Windows Update service events with separately collected client data. Initial Update State values come from the service and are replaced when client data becomes available. Service events typically arrive within an hour without client data collection. Client information requires that collection to be configured and is batch-refreshed every eight hours. <a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.</p>\n<h2>DSE recommendation</h2>\n<p>Keep service-offer processing and client-installation observations separate in the support record. Check approved data-collection configuration and timestamps before treating absent client detail as a device failure. Avoid assuming the typical service arrival time is a guaranteed deadline for client telemetry.</p>\n<h2>Verification</h2>\n<p>Follow a representative device from the service offer through actual installation, comparing the report&#8217;s Last Event Time and Last Scan Time with device evidence. Record when client detail becomes available and whether collection was enabled. Escalate a discrepancy with the relevant source and observation time, rather than repeatedly recreating the update policy. Retain installation evidence independently when reporting remains incomplete.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Reports for Windows Feature Update Policies</a>.</p>",
        "content_text": "Source facts\nIntune feature-update reports combine Windows Update service events with separately collected client data. Initial Update State values come from the service and are replaced when client data becomes available. Service events typically arrive within an hour without client data collection. Client information requires that collection to be configured and is batch-refreshed every eight hours. Microsoft Learn.\nApplicability\nUse this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.\nDSE recommendation\nKeep service-offer processing and client-installation observations separate in the support record. Check approved data-collection configuration and timestamps before treating absent client detail as a device failure. Avoid assuming the typical service arrival time is a guaranteed deadline for client telemetry.\nVerification\nFollow a representative device from the service offer through actual installation, comparing the report’s Last Event Time and Last Scan Time with device evidence. Record when client detail becomes available and whether collection was enabled. Escalate a discrepancy with the relevant source and observation time, rather than repeatedly recreating the update policy. Retain installation evidence independently when reporting remains incomplete.\nOfficial references\nMicrosoft Learn: Reports for Windows Feature Update Policies.",
        "content_markdown": "## Source facts\n\nIntune feature-update reports combine Windows Update service events with separately collected client data. Initial Update State values come from the service and are replaced when client data becomes available. Service events typically arrive within an hour without client data collection. Client information requires that collection to be configured and is batch-refreshed every eight hours. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates).\n\n## Applicability\n\nUse this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.\n\n## DSE recommendation\n\nKeep service-offer processing and client-installation observations separate in the support record. Check approved data-collection configuration and timestamps before treating absent client detail as a device failure. Avoid assuming the typical service arrival time is a guaranteed deadline for client telemetry.\n\n## Verification\n\nFollow a representative device from the service offer through actual installation, comparing the report’s Last Event Time and Last Scan Time with device evidence. Record when client detail becomes available and whether collection was enabled. Escalate a discrepancy with the relevant source and observation time, rather than repeatedly recreating the update policy. Retain installation evidence independently when reporting remains incomplete.\n\n## Official references\n\n[Microsoft Learn: Reports for Windows Feature Update Policies](https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate service and client evidence in Intune feature-update reports",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/",
                "headline": "Separate service and client evidence in Intune feature-update reports",
                "description": "Why can a feature-update report show an offer state before detailed device installation progress appears?",
                "abstract": "Why can a feature-update report show an offer state before detailed device installation progress appears?",
                "articleBody": "Source facts\nIntune feature-update reports combine Windows Update service events with separately collected client data. Initial Update State values come from the service and are replaced when client data becomes available. Service events typically arrive within an hour without client data collection. Client information requires that collection to be configured and is batch-refreshed every eight hours. Microsoft Learn.\nApplicability\nUse this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.\nDSE recommendation\nKeep service-offer processing and client-installation observations separate in the support record. Check approved data-collection configuration and timestamps before treating absent client detail as a device failure. Avoid assuming the typical service arrival time is a guaranteed deadline for client telemetry.\nVerification\nFollow a representative device from the service offer through actual installation, comparing the report’s Last Event Time and Last Scan Time with device evidence. Record when client detail becomes available and whether collection was enabled. Escalate a discrepancy with the relevant source and observation time, rather than repeatedly recreating the update policy. Retain installation evidence independently when reporting remains incomplete.\nOfficial references\nMicrosoft Learn: Reports for Windows Feature Update Policies.",
                "datePublished": "2026-09-10T00:26:48+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate service and client evidence in Intune feature-update reports"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 200,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Reports for Windows Feature Update Policies - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates"
                }
            }
        ]
    }
}