# Do not use startup scores to certify first-sign-in provisioning

> Does the endpoint startup score measure the first sign-in or update experience being investigated?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:03+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does the endpoint startup score measure the first sign-in or update experience being investigated?

## Potentially affected

Identify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.

## DSE recommendation

Write the user’s observed delay and its stage separately from the dashboard score.

## Article

## Source facts

Endpoint analytics uses the latest boot time for each device but excludes update phases. Its sign-in score excludes first sign-ins and sign-ins immediately after a feature update. Boot and sign-in events are retained for 29 days; a device without an uploaded event in that interval disappears from this report. These scoring rules define which experience is being compared. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance).

## Applicability

Identify whether the complaint concerns routine startup, initial provisioning, or the first sign-in after an update. Confirm report prerequisites and the last relevant event before selecting a metric.

## DSE recommendation

Write the user’s observed delay and its stage separately from the dashboard score. For an excluded first-sign-in scenario, arrange a controlled observation of that actual workflow instead of presenting the score as its measurement. For routine sign-in, inspect the device’s own history and the startup-process evidence before recommending a change. Keep the measured event and the business complaint linked by time and device.

## Verification

Reproduce the agreed scenario on a designated test endpoint and document when the user reaches a usable desktop. Compare only applicable report events with that observation. If the device is absent, investigate event recency and upload rather than classifying absence as fast startup. Preserve the scenario, timestamps, and observed delay without claiming that a favorable aggregate certifies every provisioning experience.

## Official references

[Microsoft Learn: Startup Performance Report in Endpoint Analytics](https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance).

## Primary reference

- Name: Startup Performance Report in Endpoint Analytics - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/endpoint-analytics/startup-performance
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not use startup scores to certify first-sign-in provisioning,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-113-do-not-use-startup-scores-to-certify-first-sign-in-provisioning/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
