# Separate service and client evidence in Intune feature-update reports

> Why can a feature-update report show an offer state before detailed device installation progress appears?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:48+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Why can a feature-update report show an offer state before detailed device installation progress appears?

## Potentially affected

Use this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.

## DSE recommendation

Keep service-offer processing and client-installation observations separate in the support record.

## Article

## Source facts

Intune feature-update reports combine Windows Update service events with separately collected client data. Initial Update State values come from the service and are replaced when client data becomes available. Service events typically arrive within an hour without client data collection. Client information requires that collection to be configured and is batch-refreshed every eight hours. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates).

## Applicability

Use this distinction when an Intune feature-update report appears to stop at an offer stage. Identify which evidence stream supplied the displayed state before diagnosing a stalled installation.

## DSE recommendation

Keep service-offer processing and client-installation observations separate in the support record. Check approved data-collection configuration and timestamps before treating absent client detail as a device failure. Avoid assuming the typical service arrival time is a guaranteed deadline for client telemetry.

## Verification

Follow a representative device from the service offer through actual installation, comparing the report’s Last Event Time and Last Scan Time with device evidence. Record when client detail becomes available and whether collection was enabled. Escalate a discrepancy with the relevant source and observation time, rather than repeatedly recreating the update policy. Retain installation evidence independently when reporting remains incomplete.

## Official references

[Microsoft Learn: Reports for Windows Feature Update Policies](https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates).

## Primary reference

- Name: Reports for Windows Feature Update Policies - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-updates/windows/monitor-feature-updates
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate service and client evidence in Intune feature-update reports,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-308-separate-service-and-client-evidence-in-intune-feature-update-reports/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
