Intune Endpoint Analytics Baseline and Remediation Plan
Intune Endpoint Analytics Baseline and Remediation Plan is a fixed-price, two-week consulting engagement that turns the Endpoint analytics data already sitting in your Microsoft Intune tenant — and Intune Advanced Analytics where you are licensed for it — into a ranked device-experience fix plan. IT Partner enables and scopes the reports, baselines startup performance, application reliability, work-from-anywhere readiness and Windows 11 hardware readiness across your enrolled Windows devices, runs device queries and anomaly checks where Advanced Analytics is present, correlates what the data shows with roughly 90 days of your helpdesk tickets, deploys Intune Remediations script packages for the top recurring issues, and hands over a report with every fix ranked by user and business impact plus a re-measure date. $2,450 fixed per project for one Intune tenant of up to 2,000 enrolled Windows devices; larger estates are quoted in writing before we start. Ongoing Intune administration, patching, monitoring and the Windows 11 migration itself are separate services, and the plan and the scripts are yours whoever does the work.
What this engagement is
Most helpdesks that fight slow boots and crashing applications are fighting them blind. The ticket says 'laptop is slow', the engineer reboots it, the ticket closes, and the same device comes back three weeks later. Meanwhile Microsoft Intune has been collecting the answer the whole time: Endpoint analytics records how long every enrolled Windows device takes to boot and sign in and which startup processes cost the most, which applications crash and how often, and whether the hardware can run Windows 11 at all. Since 1 July 2026 the picture has widened for many organizations — Microsoft added Intune Advanced Analytics, Intune Plan 2 and Remote Help to Microsoft 365 E3, and Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise Application Management to E5 on top, with eligible existing tenants receiving the entitlements by 1 August 2026, per Microsoft's announcement. An E3 or E5 tenant now owns device query, anomaly detection, battery health, the enhanced device timeline and resource performance for physical devices without buying the Intune Suite. Owning it and using it are different things. This engagement is the difference. We start by making the data trustworthy. Endpoint analytics only reports on devices that are Microsoft Entra joined or hybrid joined, running a supported Windows 10 or 11 edition, assigned the Intune data collection policy and able to reach Microsoft's diagnostic endpoints — so the first job is finding out which of your enrolled devices are actually reporting, why the rest are not (co-managed devices need Configuration Manager tenant attach; Entra-registered and personal devices never report) and fixing the enrollment gaps you approve, so the baseline covers the estate rather than the half of it that happened to be configured. Data takes up to 24 hours to land, which is why enrollment is day one. Then we baseline: the Endpoint analytics score and its three parts — startup performance, application reliability, work from anywhere — boot and sign-in times broken into core boot, Group Policy processing and sign-in with the startup processes that add the most time, application failures ranked by crash count and users affected, and the Windows 11 hardware-readiness verdict for every device with the blocking requirement named, whether that is TPM 2.0, the processor, memory, storage or Secure Boot. Where Advanced Analytics is licensed we add the anomaly report — application hangs, crashes and stop-error restarts that Microsoft's models correlate with a policy change or a deployment — battery health by model, resource performance (CPU and memory spikes) on physical devices, and device queries in Kusto Query Language to answer the questions the reports do not: which devices still have a spinning disk, which have too little memory and a particular application version, which carry a specific driver, which are logging a specific event. Then we put your helpdesk next to it. You export roughly 90 days of tickets — category, device or user, date — from whatever desk you run, and we match them to the devices, models, applications and sites the analytics flag. The overlap is the fix list; the gap in either direction is just as useful, because tickets nobody raises and slowness nobody measures both cost you people. Fixing follows measuring. Intune Remediations run a PowerShell detection script on a schedule and a remediation script only where detection says so, with per-device results in the console — the right tool for recurring, scriptable issues and the wrong one for hardware or application defects. We write, test on a pilot group and deploy script packages for the top recurring issues the baseline and the tickets agree on: the stale Group Policy refresh and Office Click-to-Run restart that Microsoft ships as built-in packages, a stuck Windows Search index, a swollen Teams or OneDrive cache, a power plan someone reset to Power saver, a startup application load nobody sanctioned, a BitLocker recovery key that never reached Entra, a time-sync drift that breaks sign-in, a disk that is nearly full — whichever your data actually names. Each package has a documented detection rule, a remediation action, a schedule, a run context, an assignment and a rollback. Remediations are licensed separately from the reports: Microsoft's licence list names Windows Enterprise E3 or E5, Education A3 or A5 and Windows VDA per user, so an E3, E5 or F3 tenant qualifies and a Business Premium tenant generally does not at the time of writing — we confirm in your tenant before promising anything. Everything else — the fixes that need a driver update, a firmware setting, an application version, a hardware replacement, a policy redesign or a network change — goes into the plan, ranked by the number of users affected, the business function they sit in and the cost of the fix, with a suggested owner for each and a date to re-measure the baseline so you can see whether the score moved. What you receive is a decision package, not a dashboard tour: a baseline workbook with the scores and the device-level detail, the ticket correlation, the deployed and documented Remediations packages, a ranked fix plan, a Windows 11 readiness list and an executive summary a non-technical leader can read in five minutes. This is a consulting deliverable, not a managed service. If you want someone to keep operating the analytics, the update rings and the scripts month after month, that is the Managed Microsoft Intune Service, and this baseline is the natural onboarding document for it. If the plan says your update pipeline is the problem, Windows Autopatch Implementation fixes that as a separate fixed-price project; if it says the tenant was never set up properly, the answer is the Microsoft Intune initial setup — our guide to mastering Microsoft Intune setup explains what 'properly' means — not more analytics. The report is written to serve your own team, us, or another provider equally: the data, the scripts and the plan are yours.
Success criteria
What you receive
How the work unfolds
Scope is confirmed in writing: the tenant, device groups and sites, and whether co-managed devices are in. We check licences — which users carry Intune Plan 1 or 2, an eligible Windows Enterprise or Education licence, and Intune Advanced Analytics — because the licence decides which reports exist and whether Remediations can run at all. We verify the Intune data collection policy assignment, device join types, Windows editions and diagnostic-endpoint connectivity, apply the enrollment fixes you approve, and request the helpdesk export. Data takes up to 24 hours to appear, so all of this happens on day one.
The Endpoint analytics score and its components, startup performance by phase and by model, application failures, work-from-anywhere metrics and Windows 11 readiness are read the way an endpoint engineer reads them — comparing models, sites, build versions and policy sets rather than staring at the tenant average. Where Advanced Analytics is licensed we review anomalies, battery health and physical-device resource performance, and run the first device queries against the devices the reports flag.
Your ticket export is matched to the analytics: which devices, models, applications and sites generate the tickets; which of them the data already explains; which tickets the data cannot see (an application defect, a network fault, a process problem); and which measured slowness has never produced a ticket. The findings are checked with your helpdesk lead, who knows which categories are honest and which mean 'someone had to pick something'.
The top recurring issues that are safely scriptable become Remediations packages: detection and remediation scripts written and tested, run context and schedule chosen, a pilot group agreed with you, results confirmed in the console. Anything that is not safely scriptable is written into the plan instead — we do not deploy a script to hide a hardware problem.
Approved packages roll out to their production assignment with monitoring. Every other finding is ranked by users affected, business function and cost of fix, with a suggested owner and, for hardware, the Windows 11 readiness verdict attached. The re-measure date is set — typically 30 days out — and what 'better' should look like is written down next to the baseline numbers.
The executive summary is presented to leadership; the engineer walkthrough covers the reports, device query, the Remediations packages and how to change or retire them; the workbook, the KQL, the scripts and the settings register are handed over and our access is removed. The re-measure itself is a short paid follow-up or something your team runs from the workbook — either is fine; the method is yours.
Prerequisites
Who does what
IT Partner
- Verify licensing, enrollment and data flow before reading a single chart, and tell you plainly which reports your licences do and do not unlock.
- Read the baseline as engineers — comparing models, sites, builds and policy sets — and write down what the numbers mean rather than what they are.
- Correlate the helpdesk export against the analytics and validate the findings with your helpdesk lead.
- Write, test and pilot every Remediations package before it reaches production, with a documented rollback and no deployment without your written approval.
- Rank every finding by users affected, business function and cost of fix, including the findings that earn us nothing — a driver from the vendor, a setting your own team can change, a device that should simply be replaced.
- Hand over the workbook, the KQL, the scripts and the settings register, present the summary to leadership and walk your engineers through the method.
- Remove our access at the end and treat everything in the data as confidential.
Your team
- Confirm scope in writing: tenant, device groups, sites, and whether co-managed devices are in.
- Grant the least-privilege Intune role, and approve the data collection policy assignment and any enrollment fixes.
- Provide the helpdesk export and make the helpdesk lead available for one validation session.
- Approve the pilot group and each Remediations package before deployment.
- Attend the leadership read-out and the engineer walkthrough.
- Decide what happens next — execute the plan with your own team, with us, or with someone else; the plan serves all three.
What's not included
Limitations & technical notes
Frequently asked questions
What does Intune Endpoint analytics actually show, and why have we never looked at it?
It shows three things for every reporting Windows device: startup performance (boot and sign-in time split into core boot, Group Policy processing and sign-in, with the startup processes that add the most), application reliability (which applications crash, how often, and how many users that touches) and work-from-anywhere readiness (cloud management, cloud identity, cloud provisioning and the Windows 11 hardware-readiness verdict). It rolls them into an Endpoint analytics score with Microsoft's insights and recommendations underneath. Most tenants have never looked because nobody assigned the data collection policy, half the devices are not reporting, and the administrator who could read it is busy answering the tickets it would prevent. The engagement fixes all three.
What is the difference between Endpoint analytics and Intune Advanced Analytics — and which do we have?
Endpoint analytics is the core set of reports that comes with Intune Plan 1 on an eligible Windows device. Intune Advanced Analytics is the licensed layer on top: device query (near-real-time Kusto queries against one device or across the estate), anomaly detection, the enhanced device timeline, battery health, resource performance for physical devices and custom device scopes. Which you have depends on the licence on the user. Microsoft 365 E3 and E5 include Advanced Analytics since 1 July 2026, the Intune Suite includes it, and it is sold as a standalone add-on — $5 per user per month at Microsoft's published list price at the time of writing; the current price is on our Intune Advanced Analytics page. Business Premium and F3 do not include it. We tell you on day one which layer you own.
We have Microsoft 365 E3. Do we already own Advanced Analytics?
Yes, once your tenant has received Microsoft's July 2026 entitlement update. Microsoft announced that from 1 July 2026 Microsoft 365 E3 includes Intune Remote Help, Intune Advanced Analytics and Intune Plan 2; that E5 additionally includes Endpoint Privilege Management, Microsoft Cloud PKI and Enterprise Application Management; and that eligible existing tenants would receive the capabilities by 1 August 2026 with at least 30 days' notice in the Message Center. Government clouds follow on a delayed schedule. We check the entitlement in your tenant rather than assume it — and if you have been paying for the Intune Suite or the standalone add-on alongside E3, the plan says so, because that is money to reclaim.
We are on Microsoft 365 Business Premium. What changes?
Business Premium carries Intune Plan 1, so the core Endpoint analytics reports — startup, application reliability, work from anywhere, Windows 11 readiness — are available on eligible devices, and that alone is usually enough to explain most slow-laptop tickets. Two things differ. Advanced Analytics is not included, so device query, anomaly detection and battery health need the standalone add-on or the Intune Suite, which we can quote at Microsoft's price. And Intune Remediations are licensed separately: Microsoft's list names Windows Enterprise E3 or E5, Education A3 or A5 and Windows VDA per user, and Business Premium is not on it at the time of writing — so for a Business Premium tenant the fix plan is the deliverable, and the scripted fixes are handed over as tested PowerShell for your team to run through Intune's platform scripts or your own tooling. We confirm against Microsoft's current documentation and your tenant before we promise anything, and the price is the same either way.
Do Intune Remediations need extra licences?
They do, separately from the reports. Microsoft requires the users of the devices to hold Windows 10/11 Enterprise E3 or E5 (included in Microsoft 365 F3, E3 and E5), Windows 10/11 Education A3 or A5 (included in Microsoft 365 A3 and A5) or Windows Virtual Desktop Access per user, and an Intune administrator has to confirm the licensing in the console before Remediations can be used for the first time. We do that check on day one. If your tenant qualifies, the packages are deployed and left running; if it does not, the scripts are still yours, delivered and documented, for use through other means.
Will this slow devices down or collect personal data?
No and no, within Microsoft's design. Endpoint analytics uses the Windows diagnostic data devices already generate at the required level — boot timings, application crash events, hardware inventory — sent to Microsoft's diagnostic endpoints; it does not capture browsing, keystrokes, documents or screen content, and the overhead on the device is negligible. Device queries read configuration and inventory from the device, not user files. We assign the data collection policy only with your written approval, document exactly what it enables in the settings register, and support your privacy or works-council review with Microsoft's own documentation.
We already know our laptops are slow. How does data change anything?
Because 'slow' has at least six causes and each has a different fix. Startup performance tells you whether it is a spinning disk (replace the device), a bloated Group Policy set (fix policy), five startup applications nobody sanctioned (a Remediations package), a sign-in script from 2014 (retire it) or a build that behaves badly on one model (a driver or firmware update). Application reliability tells you whether the crashes are one application, one version, one model or one site. The model breakdown is usually the revelation: the fleet average looks fine and one model with 300 users is dragging it. Data turns 'buy everyone new laptops' into 'replace these 80 and fix policy for the rest' — and the plan writes down which is which.
What is Intune device query and how do you use it here?
Device query is part of Intune Advanced Analytics: a Kusto Query Language query run against a single online device for near-real-time inventory, configuration, registry, event and process data — and, across multiple devices, against the estate. We use it to answer the questions the reports do not: which devices have less than a given amount of memory or a spinning disk, which run a specific application version or driver, which have a particular service stopped or a registry value set, which have logged a specific event since Monday. Every query we run is kept in the workbook so your team can rerun it. Devices must be enrolled in Endpoint analytics and online, and the administrator needs the query permission — both set up in the first days.
How do you correlate with our helpdesk tickets, and what do you need from us?
An export of roughly 90 days of tickets with category, device name or user, and date — from whatever desk you run; a spreadsheet is fine. We match tickets to devices, device models, applications and sites, then set out three lists: tickets the analytics explain (the fix list), tickets the analytics cannot see (an application defect, a network fault, a process problem — routed to the right owner) and measured slowness that never produced a ticket (the users who stopped complaining). We validate the result with your helpdesk lead, who knows which categories are real and which mean 'someone had to pick something'.
How many remediation scripts do you deploy, and who owns them afterwards?
Up to five Remediations packages within the fixed fee, chosen from the issues the baseline and the tickets agree on and that are safely scriptable — more are quoted. Each is a detection script and a remediation script, tested, piloted on a group you approve, deployed to its production assignment with a schedule and run context, and documented with its purpose, logic, assignment and rollback. They are yours: they run in your tenant under your control, your team can edit or retire them, and nothing ties you to us. If you buy your Microsoft licensing through IT Partner, break-fix support during business hours is included at no extra charge, so a package that starts misbehaving after we leave is a ticket, not a quote.
Does it tell us which devices cannot run Windows 11?
Yes. The work-from-anywhere report's Windows metric gives a hardware-readiness verdict for every reporting device and names the requirement that blocks the rest — TPM 2.0, processor, memory, storage or Secure Boot — with a view of the top blockers across the estate. Windows 10 left support on 14 October 2025, per Microsoft's product lifecycle, so any Windows 10 device still in the estate is either on Extended Security Updates or unpatched; the readiness list tells you which of them can upgrade and which need replacing. The upgrade itself is a separate project.
We co-manage with Configuration Manager. Does this work?
Yes, with a prerequisite: co-managed devices report into Endpoint analytics through Configuration Manager tenant attach with Endpoint analytics enabled, and that has to be in place before the baseline is meaningful. We check it on day one and either confirm it or list what has to change. If the conclusion is that the estate is ready to leave Configuration Manager behind altogether, that is a separate conversation and a separate project.
What happens after the two weeks?
Three things can happen, and the plan is written for all of them. Your team executes the plan and runs the re-measure from the workbook on the date we set. Or you ask us to run the re-measure as a short paid follow-up and to quote the fixes that need engineering. Or you hand the estate to the Managed Microsoft Intune Service, which takes the baseline as its onboarding document and keeps the analytics, the update rings and the Remediations packages operated month after month. None of those is assumed by the fee, and there is no minimum term on anything that follows.
Is this the same as the Devices monitoring service?
No. Devices monitoring installs an agent and watches computers and network equipment continuously, with alerting and a regular report — an operations service. Endpoint analytics is Microsoft's built-in Windows telemetry with up to a day of latency, and this engagement is a one-time baseline and fix plan built on it. They are complementary: the baseline often tells you exactly which checks the monitoring should carry.
How is the fee structured, and when do we pay?
$2,450, fixed, per project, for one Intune tenant of up to 2,000 enrolled Windows devices and up to five Remediations packages; larger estates or a longer remediation list get a fixed written quote before anything starts. You pay after you approve delivery. Microsoft licences you may need — Intune Plan 2, Intune Advanced Analytics, the Intune Suite, Windows Enterprise — are Microsoft's subscriptions at Microsoft's price and are never part of this fee.