GuideInformationCybersecurityIT

Separate Configuration Manager analytics collection from cloud upload

Does enabling local Endpoint analytics collection in Configuration Manager also authorize cloud upload?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 1 min read
Executive summary

What you need to know

Does enabling local Endpoint analytics collection in Configuration Manager also authorize cloud upload?

Potentially affected

Apply this review to Endpoint analytics for Configuration Manager-managed devices. Identify any co-management and custom client-settings assignments before following the corresponding configuration path.

DSE recommendation

Record local collection and cloud upload as separate configuration decisions.

Source facts

Configuration Manager’s Endpoint analytics client setting controls local collection, not whether that data is uploaded to the cloud. Cloud upload is configured separately. Enabling upload automatically updates the default client settings, but existing custom client settings may need updating and redeployment. Devices managed only by Configuration Manager do not require the Intune data collection policy. Microsoft Learn.

Applicability

Apply this review to Endpoint analytics for Configuration Manager-managed devices. Identify any co-management and custom client-settings assignments before following the corresponding configuration path.

DSE recommendation

Record local collection and cloud upload as separate configuration decisions. Have the service owner identify which devices should collect data, which should contribute to the cloud service and which client settings actually reach them. Inspect custom assignments instead of assuming a change to the default configuration reached every device. Keep the approved telemetry scope with the rollout record, and use the documented management path for each cohort.

Verification

In a controlled cohort, inspect the effective client setting, its deployment result and the separate upload configuration. Confirm that the intended devices produce the expected analytics data after processing. If data is missing, identify whether collection, assignment or upload is the unresolved step before broadening the target population. A local collection setting alone should not close the cloud-reporting acceptance check.

Official references

Microsoft Learn: Configure Endpoint Analytics.

Primary reference

Review the official source

Configure Endpoint Analytics - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE