# Label the comparison baseline before interpreting endpoint scores

> Is an endpoint score being compared with the intended reference?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:47+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Is an endpoint score being compared with the intended reference?

## Potentially affected

Identify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.

## DSE recommendation

Record the reference name and capture time alongside the score.

## Article

## Source facts

Endpoint analytics scores run from zero to 100, with lower values indicating improvement opportunities. The built-in All organizations median uses anonymized, aggregated scores and is kept current. Administrators can create baselines from their own current metrics. Microsoft also notes that detailed device or model reporting can differ slightly from less-granular scores. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores).

## Applicability

Identify the report, metric, device population, and baseline selected for the discussion. Distinguish an external comparison with a typical organization from a comparison intended to track your own change.

## DSE recommendation

Record the reference name and capture time alongside the score. For a planned improvement, preserve the starting measurements and define which user experience should change, rather than choosing a more favorable comparison after the work. Inspect the metric breakdown and relevant devices before presenting the aggregate as an explanation of the problem. Keep peer benchmarking separate from evidence that a specific intervention worked.

## Verification

Return to the same report and intended population for the follow-up comparison. Check that the selected baseline and metric definition match the review record. Investigate differences between overview and detailed views before treating them as contradictory results. Pair the score comparison with an approved observation of the affected workflow, and state any population or usage changes. Report the measured result without converting a dashboard recommendation into a guaranteed improvement.

## Official references

[Microsoft Learn: Scores, Baselines, and Insights in Endpoint Analytics](https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores).

## Primary reference

- Name: Scores, Baselines, and Insights in Endpoint Analytics - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/endpoint-analytics/scores
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Label the comparison baseline before interpreting endpoint scores,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-309-label-the-comparison-baseline-before-interpreting-endpoint-scores/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
