# Name the device cohort before sharing endpoint analytics results

> Which device population is actually represented by the selected analytics scope?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:53+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which device population is actually represented by the selected analytics scope?

## Potentially affected

Identify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.

## DSE recommendation

Name the scope after its intended population and record the underlying tag identifier.

## Article

## Source facts

Endpoint analytics custom device scopes filter supported reports using one scope tag. They start disabled, can need up to 24 hours after activation, and require at least ten devices. A selected scope persists across supported report pages. Deleting its underlying tag breaks the scope. The supported reports listed are startup, work-from-anywhere, application reliability, and battery health. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes).

## Applicability

Identify the audience for the report and the actual tag membership. Check report support explicitly rather than assuming every analytics page can use the same saved cohort.

## DSE recommendation

Name the scope after its intended population and record the underlying tag identifier. Have the endpoint owner review membership before activating it. Include the selected scope in screenshots, exports, and discussions so an audience-specific score is not presented as the whole organization. Coordinate tag cleanup with report owners rather than treating the tag as an unused label.

## Verification

After processing, compare a known included device and an excluded device with the intended population. Move between supported reports and confirm that the selected scope remains the expected one. When returning to an organization-wide review, explicitly choose All Devices and verify the change. Record processing or insufficient-data states separately from a measured poor result. Preserve the scope definition with the analysis so later readers can explain which endpoints the conclusion represents.

## Official references

[Microsoft Learn: Device Scopes](https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes).

## Primary reference

- Name: Device Scopes - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/advanced-analytics/device-scopes
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Name the device cohort before sharing endpoint analytics results,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-303-name-the-device-cohort-before-sharing-endpoint-analytics-results/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
