Skip to main content

IBP – HARDEN – Windows – Endpoint Analytics

Best Practice Policies M1

🎯 Purpose

✅ Enable Endpoint Analytics by allowing Windows Health Monitoring on all Windows devices.

➡️ This supports Essential Eight–aligned operational visibility by providing insight into device boot performance and Windows Update reliability, without impacting users or enabling unnecessary telemetry.


👥 Who is affected

Devices: All Windows 10/11 devices
🚫 Exclusions: None

➡️ Every enrolled Windows device reports health data required for Endpoint Analytics.


☁️ What data is collected

Signals collected:

  • Boot and sign‑in performance

  • Windows Update history and reliability

🚫 Not collected:

  • App health telemetry

  • Endpoint classification data

  • Custom or expanded device signals

➡️ Only the minimum essential dataset required for Endpoint Analytics is enabled.


🔧 How Endpoint Analytics is enabled

✅ Windows Health Monitoring is enabled at the OS level
✅ Monitoring scope limited to:

  • Boot performance

  • Windows Updates

➡️ This allows Intune to surface high‑value analytics while keeping telemetry tightly scoped.

ℹ️ Note: No custom monitoring scopes are configured.


⚙️ What this policy does NOT enforce

🚫 App health monitoring
🚫 Device reliability or process telemetry
🚫 Remote analytics signals
🚫 Custom analytics scopes

➡️ This is intentional to keep the policy lightweight and suitable for organisation‑wide deployment.


🟢 Policy status

✅ Enabled
✅ Actively collecting Endpoint Analytics data


📘 Essential Eight Alignment

✅ Supports Essential Eight – Operational Visibility (Maturity Level 1)
✅ Enables measurement of:

  • Patch compliance

  • Update reliability

  • Device startup performance

ℹ️ Advanced analytics and extended telemetry are addressed in higher maturity levels.


📘 Practical Interpretation (Executive‑Friendly)

This configuration policy ensures that:

✅ All Windows devices
✅ Provide basic health and update telemetry
✅ Enabling Endpoint Analytics insights in Intune

This delivers immediate operational value — such as identifying slow boot devices and update failures — while maintaining a minimal, non‑intrusive telemetry footprint aligned to Essential Eight Maturity Level 1.

Did this answer your question?