{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
        "slug": "dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/"
        },
        "title": "Label the comparison baseline before interpreting endpoint scores",
        "summary": "Is an endpoint score being compared with the intended reference?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:47+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Identify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.",
        "dse_recommendation": "Record the reference name and capture time alongside the score.",
        "primary_source": {
            "name": "Scores, Baselines, and Insights in Endpoint Analytics - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Endpoint analytics scores run from zero to 100, with lower values indicating improvement opportunities. The built-in All organizations median uses anonymized, aggregated scores and is kept current. Administrators can create baselines from their own current metrics. Microsoft also notes that detailed device or model reporting can differ slightly from less-granular scores. <a href=\"https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.</p>\n<h2>DSE recommendation</h2>\n<p>Record the reference name and capture time alongside the score. For a planned improvement, preserve the starting measurements and define which user experience should change, rather than choosing a more favorable comparison after the work. Inspect the metric breakdown and relevant devices before presenting the aggregate as an explanation of the problem. Keep peer benchmarking separate from evidence that a specific intervention worked.</p>\n<h2>Verification</h2>\n<p>Return to the same report and intended population for the follow-up comparison. Check that the selected baseline and metric definition match the review record. Investigate differences between overview and detailed views before treating them as contradictory results. Pair the score comparison with an approved observation of the affected workflow, and state any population or usage changes. Report the measured result without converting a dashboard recommendation into a guaranteed improvement.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Scores, Baselines, and Insights in Endpoint Analytics</a>.</p>",
        "content_text": "Source facts\nEndpoint analytics scores run from zero to 100, with lower values indicating improvement opportunities. The built-in All organizations median uses anonymized, aggregated scores and is kept current. Administrators can create baselines from their own current metrics. Microsoft also notes that detailed device or model reporting can differ slightly from less-granular scores. Microsoft Learn.\nApplicability\nIdentify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.\nDSE recommendation\nRecord the reference name and capture time alongside the score. For a planned improvement, preserve the starting measurements and define which user experience should change, rather than choosing a more favorable comparison after the work. Inspect the metric breakdown and relevant devices before presenting the aggregate as an explanation of the problem. Keep peer benchmarking separate from evidence that a specific intervention worked.\nVerification\nReturn to the same report and intended population for the follow-up comparison. Check that the selected baseline and metric definition match the review record. Investigate differences between overview and detailed views before treating them as contradictory results. Pair the score comparison with an approved observation of the affected workflow, and state any population or usage changes. Report the measured result without converting a dashboard recommendation into a guaranteed improvement.\nOfficial references\nMicrosoft Learn: Scores, Baselines, and Insights in Endpoint Analytics.",
        "content_markdown": "## Source facts\n\nEndpoint analytics scores run from zero to 100, with lower values indicating improvement opportunities. The built-in All organizations median uses anonymized, aggregated scores and is kept current. Administrators can create baselines from their own current metrics. Microsoft also notes that detailed device or model reporting can differ slightly from less-granular scores. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores).\n\n## Applicability\n\nIdentify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.\n\n## DSE recommendation\n\nRecord the reference name and capture time alongside the score. For a planned improvement, preserve the starting measurements and define which user experience should change, rather than choosing a more favorable comparison after the work. Inspect the metric breakdown and relevant devices before presenting the aggregate as an explanation of the problem. Keep peer benchmarking separate from evidence that a specific intervention worked.\n\n## Verification\n\nReturn to the same report and intended population for the follow-up comparison. Check that the selected baseline and metric definition match the review record. Investigate differences between overview and detailed views before treating them as contradictory results. Pair the score comparison with an approved observation of the affected workflow, and state any population or usage changes. Report the measured result without converting a dashboard recommendation into a guaranteed improvement.\n\n## Official references\n\n[Microsoft Learn: Scores, Baselines, and Insights in Endpoint Analytics](https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Label the comparison baseline before interpreting endpoint scores",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/",
                "headline": "Label the comparison baseline before interpreting endpoint scores",
                "description": "Is an endpoint score being compared with the intended reference?",
                "abstract": "Is an endpoint score being compared with the intended reference?",
                "articleBody": "Source facts\nEndpoint analytics scores run from zero to 100, with lower values indicating improvement opportunities. The built-in All organizations median uses anonymized, aggregated scores and is kept current. Administrators can create baselines from their own current metrics. Microsoft also notes that detailed device or model reporting can differ slightly from less-granular scores. Microsoft Learn.\nApplicability\nIdentify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.\nDSE recommendation\nRecord the reference name and capture time alongside the score. For a planned improvement, preserve the starting measurements and define which user experience should change, rather than choosing a more favorable comparison after the work. Inspect the metric breakdown and relevant devices before presenting the aggregate as an explanation of the problem. Keep peer benchmarking separate from evidence that a specific intervention worked.\nVerification\nReturn to the same report and intended population for the follow-up comparison. Check that the selected baseline and metric definition match the review record. Investigate differences between overview and detailed views before treating them as contradictory results. Pair the score comparison with an approved observation of the affected workflow, and state any population or usage changes. Report the measured result without converting a dashboard recommendation into a guaranteed improvement.\nOfficial references\nMicrosoft Learn: Scores, Baselines, and Insights in Endpoint Analytics.",
                "datePublished": "2026-09-10T00:26:47+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Label the comparison baseline before interpreting endpoint scores"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Scores, Baselines, and Insights in Endpoint Analytics - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores"
                }
            }
        ]
    }
}