What you need to know
What should an administrator establish before acting on an anomaly correlation group?
Potentially affected
Check the reported anomaly, severity, first detection, and last occurrence. Identify the business workflow affected before deciding how much investigation priority the alert deserves.
DSE recommendation
Write a testable explanation for the shared attribute instead of treating correlation as a demonstrated cause.
Source facts
Advanced Analytics flags application hangs, crashes, and Stop Error Restarts. Its device correlation groups use shared attributes such as app version, driver update, operating system, or model, and show affected and at-risk devices. Cohorts are identified only for medium- and high-severity anomalies. The threshold-based model’s thresholds are predetermined rather than administrator-adjustable. Microsoft Learn.
Applicability
Check the reported anomaly, severity, first detection, and last occurrence. Identify the business workflow affected before deciding how much investigation priority the alert deserves.
DSE recommendation
Write a testable explanation for the shared attribute instead of treating correlation as a demonstrated cause. Compare an affected example with a suitable unaffected one, and ask the relevant owner about recent changes. Use the device timeline and supporting resource evidence to challenge the explanation. Record competing causes and any missing observations rather than forcing every incident into the first suggested group.
Verification
Reproduce the suspected failure in an approved test population and evaluate a bounded remedy there. Check that the relevant user workflow improves before expanding that remedy to devices merely classified as at risk. Revisit the anomaly report and retain the affected population, shared attribute, observation window, and outcome. If the evidence does not support the proposed cause, close or redirect that hypothesis without presenting the original correlation as a confirmed diagnosis.
Official references
Microsoft Learn: Anomalies Report for Proactive Device Issue Detection.
Review the official source
Anomalies Report for Proactive Device Issue Detection - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE