# Separate Configuration Manager analytics collection from cloud upload

> Does enabling local Endpoint analytics collection in Configuration Manager also authorize cloud upload?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-198-separate-configuration-manager-analytics-collection-from-cloud-upload/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:38+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 1 minutes

## What you need to know

Does enabling local Endpoint analytics collection in Configuration Manager also authorize cloud upload?

## Potentially affected

Apply this review to Endpoint analytics for Configuration Manager-managed devices. Identify any co-management and custom client-settings assignments before following the corresponding configuration path.

## DSE recommendation

Record local collection and cloud upload as separate configuration decisions.

## Article

## Source facts

Configuration Manager’s Endpoint analytics client setting controls local collection, not whether that data is uploaded to the cloud. Cloud upload is configured separately. Enabling upload automatically updates the default client settings, but existing custom client settings may need updating and redeployment. Devices managed only by Configuration Manager do not require the Intune data collection policy. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/endpoint-analytics/configure).

## Applicability

Apply this review to Endpoint analytics for Configuration Manager-managed devices. Identify any co-management and custom client-settings assignments before following the corresponding configuration path.

## DSE recommendation

Record local collection and cloud upload as separate configuration decisions. Have the service owner identify which devices should collect data, which should contribute to the cloud service and which client settings actually reach them. Inspect custom assignments instead of assuming a change to the default configuration reached every device. Keep the approved telemetry scope with the rollout record, and use the documented management path for each cohort.

## Verification

In a controlled cohort, inspect the effective client setting, its deployment result and the separate upload configuration. Confirm that the intended devices produce the expected analytics data after processing. If data is missing, identify whether collection, assignment or upload is the unresolved step before broadening the target population. A local collection setting alone should not close the cloud-reporting acceptance check.

## Official references

[Microsoft Learn: Configure Endpoint Analytics](https://learn.microsoft.com/en-us/intune/endpoint-analytics/configure).

## Primary reference

- Name: Configure Endpoint Analytics - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/endpoint-analytics/configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Configuration Manager analytics collection from cloud upload,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-198-separate-configuration-manager-analytics-collection-from-cloud-upload/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
