Microsoft Intune
Device enrollment

Learn about using Intune to manage Microsoft Defender settings on devices that aren't enrolled with Intune

In brief

Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/security-settings-management.md.

What Intune admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Open the full-page diff for complete context.

The Defender for Endpoint security settings management scenario is supported in the following government tenants:

  • US Government Community Cloud (GCC)
  • US Government Community High (GCC High)
  • Department of Defense (DoD)

For more information, see:

In the Microsoft Intune admin center, your account needs permissions equal to Endpoint Security Manager built-in Role based access control (RBAC) role.

  1. Sign in to the Microsoft Intune admin center.

  2. Select Endpoint security > Microsoft Defender for Endpoint, and set Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations to On.

After devices onboard to Defender for Endpoint, you'll need to create device groups to support deployment of policy for Microsoft Defender for Endpoint. To identify devices that have enrolled with Microsoft Defender for Endpoint but aren't managed by Intune or Configuration Manager:

  1. Sign in to Microsoft Intune admin center.

  2. Go to Devices > All devices, and then select the column Managed by to sort the view of devices.

Microsoft Intune supports deploying multiple instances of each endpoint security policy type to the same device, with each policy instance being received by the device separately. Therefore, a device might receive separate configurations for the same setting from different policies, which results in a conflict. Some settings (like Antivirus Exclusions) merge on the client and apply successfully.

  1. Sign in to the Microsoft Intune admin center.

  2. Go to Endpoint security, select the type of policy you want to configure, and then select Create Policy.

The Policy sync button only appears for devices that are successfully managed by Microsoft Defender for Endpoint.

Devices protected by tamper protectioncontrolled configuration

If a device hasThe Controlled Configuration (Device) setting in the Windows Security experience profile for Antivirus policy supersedes the previous standalone tamper protection turned on, itsetting. This setting supports both tamper protection and the broader controlled configuration mode:

  • When set to Tamper Protection (On), the behavior is identical to the previous tamper protection setting. Tamper-protected settings are locked to their secure defaults. It isn't possible to edit the values of tamper-protected settings without disabling Tamper Protectionchanging this setting first.
  • When set to Controlled Configuration (On), settings delivered by Intune take exclusive precedence over other management sources like Group Policy or Configuration Manager.

Controlled configuration is also supported for devices managed through Microsoft Defender for Endpoint security settings management. For details on how to configure controlled configuration and its scope, see Controlled configuration for Microsoft Defender settings.

Assignment Filters and security settings management

You can delete devices that use this flow using one of two methods:

  • From within the Microsoft Intune admin center go to Devices > All devices, select a device that displays either MDEJoined or MDEManaged in the Managed by column, and then select Delete.
  • You can also remove devices from the scope of Configuration Management in the Security Center.

Once a device is removed from either location, that change propagates to the other service.

\ No newline at end of file

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.