# Preserve Update Manager evidence before its query windows expire

> Plan evidence retrieval around the separate assessment and installation history windows in Azure Resource Graph.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:53+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Plan evidence retrieval around the separate assessment and installation history windows in Azure Resource Graph.

## Potentially affected

Reports and evidence exports using Azure Update Manager operations data in Azure Resource Graph.

## DSE recommendation

Set an evidence-export cadence that fits both history windows and keep assessment records separate from installation results.

## Article

## Source facts

Microsoft’s Update Manager guidance specifies seven days of recent assessment history and 30 days of installation history available through Resource Graph. These are different windows; a report should not assume the longer installation window also covers assessments.

The documented assessment records distinguish an operation-level summary from individual available software updates. Installation records likewise distinguish the run summary from individual update results. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/update-manager/query-logs).

## Applicability

Identify the report’s required period, machine population, record types, and evidence owner. Separate a current assessment question from proof of an earlier installation; absence outside the query window should remain an evidence limitation.

## DSE recommendation

DSE recommends exporting the required results before the shorter relevant window closes and retaining them under the organization’s approved evidence policy. Preserve machine identity, operation identity, record type, and timestamps so later reviewers can reconnect summary and per-update evidence. Make a missed export visible rather than filling the historical gap with current state.

## Verification

Test retrieval for known assessment and installation operations, comparing summary rows with their per-update records. Check the report’s date boundaries and confirm an intentionally out-of-window query is labeled appropriately. Verify that the retained export remains readable and attributable after the live query no longer supplies the original records.

## Official references

[Microsoft Learn: Query Resources with Azure Resource Graph in Azure Update Manager](https://learn.microsoft.com/en-us/azure/update-manager/query-logs). Source retrieved September 9, 2026.

## Primary reference

- Name: Query Resources with Azure Resource Graph in Azure Update Manager | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/update-manager/query-logs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve Update Manager evidence before its query windows expire,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-183-preserve-update-manager-evidence-before-its-query-windows-expire/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
