Everyone agrees the computers feel slow. Endpoint analytics replaces the feeling with a number.
Boot times, sign-in delays and application crashes become scores on a 0 to 100 scale, benchmarked against an anonymized median of every enrolled organization, with a ranked recommendation list that quantifies the points each fix returns. Scores exist per device and per model too, so slow stops being an opinion and becomes a sortable column, including the column that decides which hardware gets replaced next.

- 0-100The scale; lower means work to do
- Five devicesReporting minimum for any score
- Median baselineEvery enrolled org, anonymized
- Points per fixEach recommendation quantifies its gain
Seven mechanics behind the scores, and why each one matters.
One scale for everything: 0 to 100
Every metric lands on the same 0 to 100 scale, where a lower score signals room for improvement. The compression is deliberate and useful. Raw millisecond timings need an engineer to interpret; a score can go into a leadership deck, be trended month over month, and be compared across categories without translation.
A benchmark built from everyone else's telemetry
Charts carry triangle markers showing baselines, including the built-in all organizations median that positions you against a typical enterprise. Microsoft maintains it by anonymizing and aggregating scores across every enrolled organization, and documents that contributing is reversible: you can stop gathering data whenever you choose.
A to-do list that prices its own entries
The insights and recommendations pane ranks improvements and filters itself to whichever report you are viewing. Each entry carries two published details: the steps that raise the score, and the number of points the score gains once the work completes. That second detail converts prioritization from debate into arithmetic.
Individual machines, exposed by name
Per device scores exist so problems get found and resolved before the affected user ever contacts the helpdesk, which is how Microsoft frames them. Drilling into a device reveals boot history and sign-in history under startup performance plus an application reliability tab flagging troublesome desktop applications on that specific machine.
Hardware models ranked by lived experience
Model-level scores appear throughout the endpoint analytics reports, and the documentation names their purpose directly: projecting and prioritizing the next hardware refresh cycle and spotting devices that no longer meet your current hardware specifications. Refresh planning driven by measured experience beats refresh planning driven by purchase dates.
Stacked filters that isolate a cause
The documentation walks through it: open the device performance tab of the startup performance report, filter to devices with high time to responsive desktop, then layer on a filter for high Group Policy sign-in time. What remains is a measured answer to how much Group Policy is costing your slowest machines.
The floor, and two quirks worth knowing
Below five reporting devices the status reads insufficient data and no meaningful score exists. Two filter limitations are also published: the disk type filter rejects the value unknown, and filtering on startup performance score from the overview device scores view returns devices showing a blank double-dash score. Small mismatches between detailed reports and the rounded scores are documented as normal.
Microsoft's own worked example shows how the numbers are meant to be read.
The documentation includes a short investigation narrative, and following it teaches the reading technique better than any feature list.
- Step one, position: the example finds an overall startup score of 61 against the all organizations baseline of 50. Before any diagnosis begins, the estate knows it stands above a typical enterprise, which frames everything that follows.
- Step two, isolate: the breakdown shows the core boot phase scoring 77. Whatever is bothering users, it is not the hardware booting slowly, and the costliest fix, replacing machines, just fell off the suspect list.
- Step three, name the cause: the average time to reach a responsive desktop points to long-running startup processes dragging the core sign-in score down to 46, and the top entry in insights and recommendations confirms exactly that.
- Position, isolate, confirm, with the point value of the fix printed beside it. Few operational tools hand you both the diagnosis and the justification for acting on it in the same screen.
Four habits that separate a used tool from an enabled one.
The point values set the work order
Every insight publishes how many points completing it returns, which is a prioritization signal most operational tools never provide. We execute the list strictly in descending point order with a named owner per entry, because that is the sequence that moves the visible number fastest and keeps sponsors engaged.
Model rankings go to the people holding the budget
The documentation positions model scores as input for projecting the next refresh cycle and catching devices below current specification. We package that ranking for whoever approves hardware spend, replacing age-based refresh logic with experience-based logic, which is both cheaper and easier to defend line by line.
The before picture gets captured first
A custom baseline snapshots your metrics at a moment you choose, and its whole value depends on that moment preceding the work. We record it on day one, before any remediation, so every later gain is measured against evidence rather than memory. Skip this and the improvement story is forever anecdotal.
The device view lands inside the service desk workflow
Boot history, sign-in history and application reliability per named machine mean a technician can open a ticket already briefed on what the device has been doing for weeks. We wire that view into the desk's standard triage, which shortens calls and occasionally eliminates them, since flagged machines can be fixed proactively.
Six US scenarios where measurement ends a stalemate.
Defending a hardware refresh line item
Model scores span every endpoint analytics report, and the documentation ties them explicitly to refresh planning and to finding devices below current specification. A proposal listing models ranked by measured user experience, worst first, gives a CFO something to approve rather than something to postpone.
Breaking the deadlock between users and IT
Users insist the machines crawl; IT sees nothing wrong. The median comparison answers whether the estate is actually below par, and the phase breakdown answers where. In Microsoft's worked example the split was stark: boot at 77, sign-in at 46, indicting startup processes while clearing the hardware entirely.
Demonstrating that an Intune migration delivered
Capture a custom baseline at go-live and the monthly score movement becomes the program's scoreboard, independent of milestones and device counts. Insights completed along the way each carry their published point value, so the delivered improvement has receipts attached.
Recovering minutes lost at every shift change
In operations where workers authenticate repeatedly through the day, sign-in delay is a throughput cost, not an annoyance. The documented filter technique, high time to responsive desktop stacked with high Group Policy sign-in time, measures exactly how much policy processing contributes and on how many machines.
Shared clinical workstations under constant sign-in churn
A machine that cycles through users all day multiplies every startup and sign-in defect by every rotation, and in a care setting those minutes accumulate across shifts. Device scores name the worst machines, and the per-device application reliability tab usually locates the true complaint: the clinical application, not the hardware.
Making sense of a fleet bought piecemeal over years
Districts, campuses and fast-grown companies accumulate hardware from many budgets and many vendors. Model scores collapse that sprawl into a single ranked list, and stacked filters reveal what the poorly performing machines share, turning isolated complaints into one addressable pattern.
How device experience gets judged in US organizations today.
| Feature | Measured with endpoint analytics | Anecdote and ticket volume | No visibility at all |
|---|---|---|---|
Startup experience quantified | Yes | No | No |
Application reliability quantified | Yes | No | No |
Benchmarked against other organizations | Yes | No | No |
Progress demonstrable over time | Yes | No | No |
Fixes ranked by quantified return | Yes | No | No |
Problem machines identifiable by name | Yes | Only via complaints | No |
Refresh decisions backed by measurement | Yes | No | No |
Issues caught ahead of the helpdesk call | Sometimes | No | No |
Presentable to a non-technical audience | Yes | Weakly | No |
Cost to obtain | Configuration | Not applicable | Not applicable |
Seven surfaces, each built for a different question.
View
Organization score
- What it shows
- Overall 0 to 100 scores with phase breakdowns, judged against the all organizations median
- The question it answers
- Where do we stand next to a typical enterprise, and in which phase
View
Custom baselines
- What it shows
- Snapshots of your own metrics at a chosen moment, drawn as triangle markers
- The question it answers
- Have we moved forward or slipped back since then
View
Insights and recommendations
- What it shows
- A ranked improvement list, scoped to the current report, each entry pricing its gain in points
- The question it answers
- What comes first, and what is finishing it worth
View
Device scores
- What it shows
- Sortable per-machine scores with boot history, sign-in history and application reliability behind each
- The question it answers
- Which exact machines are hurting which users
View
Model scores
- What it shows
- Experience scores rolled up per hardware model, present across all the reports
- The question it answers
- Which models to refresh first, and which no longer meet spec
View
Report filters
- What it shows
- Stackable conditions on report tables, such as slow desktop arrival combined with high Group Policy sign-in time
- The question it answers
- What the worst machines share in common
View
User experience page
- What it shows
- The analytics, startup and reliability picture for a single named device
- The question it answers
- What has this specific complaining user's machine been doing
Five steps, with the snapshot deliberately ahead of the repairs.
- 1
Prove the data is real before trusting it
Confirm at least five devices report, since the documented floor below that is an insufficient data status with no meaningful score. Confirm Windows health monitoring feeds the pipeline. Then audit whether the reporting population resembles the estate, because a score describes only the machines that report into it.
- 2
Freeze the starting position
The median baseline locates you against a typical enterprise; a custom baseline locates you against yourself. We capture the custom one before touching anything, because a baseline taken mid-remediation can never prove what the remediation achieved. It is a two minute action with a permanent payoff.
- 3
Execute insights by descending point value
Each recommendation publishes its steps and its point yield on completion. We work top down, one named owner per item, and since the insight pane filters itself to the report in view, startup performance and application reliability each get their own ranked queue and the same treatment.
- 4
Route the device and model views to their audiences
The service desk receives the per-device view, putting boot history, sign-in history and application reliability in front of technicians before tickets get worked. Hardware decision makers receive the model ranking as standing evidence for refresh sequencing and for flagging models that have aged out of specification.
- 5
Install the monthly rhythm
One recurring review: movement against both baselines, the current top insights with their owners, and the model ranking. Because the score reads instantly to non-technical audiences, it earns a line in the business report, which is what keeps the whole practice funded and alive after we step back.
What organizations ask about endpoint analytics.
Fifteen checks between switching it on and getting value out.
Getting data
- Five or more devices reporting?The documented floor for any score at all.
- Windows health monitoring switched on?The event pipeline the scores depend on.
- Reporting population representative of the estate?Scores describe reporters, not the fleet.
- Position on contributing to the median decided?Data gathering can be stopped at any time.
- Custom baseline captured yet?Without one, improvement stays unprovable.
Reading it
- Above or below the median, and by how much?The built-in comparison point.
- Which phase is the drag: boot or sign-in?They score independently.
- Top three insights reviewed?Each carries its own point value.
- Worst-scoring models identified?The refresh queue in embryo.
- Outlier devices pulled from the sort?Names, not averages, drive fixes.
Acting on it
- Top recommendation assigned to a person?Unowned findings decay into wallpaper.
- Score included in a leadership report?It needs no translation for executives.
- Monthly review on the calendar?Trend beats snapshot every time.
- Service desk trained on the device view?Context before the ticket is even opened.
- Model ranking shared with procurement?Refresh decisions deserve measured input.
The pages around this one.
Windows Autopatch
Managed update rings, often the destination once a reliability finding points at patching.
Intune configuration profiles
The remediation path when the filters implicate policy processing in slow sign-ins.
Microsoft Intune
The platform hub, and the context endpoint analytics operates inside.
Open the console and compare your score to the median, today.
Above it, you have a result worth reporting upward. Below it, you have the ranked to-do list and the evidence to fund working through it. Both outcomes beat another quarter of unresolvable complaints about slow machines.
Related Services
Explore more solutions that work great with this service