Blog Post

Microsoft Defender for Endpoint Blog
2 MIN READ

Announcing Preview of New Security Management Capabilities for Microsoft Defender for Endpoint.

Efrat Kliger's avatar
Efrat Kliger
Icon for Microsoft rankMicrosoft
Dec 03, 2021

Preventing data breaches and maintaining compliance are at the top of everyone's agenda. It is essential for IT teams and security teams to collaborate and become true, unified partners when it comes to business enablement.
Microsoft is privileged to sit at the intersection of IT and Security, and continually looks for opportunities to better integrate security and IT management, from configuration and device management to compliance.

We are excited to announce that Microsoft Defender for Endpoint has extended its configuration management capabilities. Together with Microsoft Endpoint Manager, we’ve integrated security management in a single, dedicated console for unified endpoint security management. Without the need to deploy and use additional tools and infrastructure, you can now manage security settings (initially AV, EDR and firewall policies) across devices, with Microsoft Endpoint Manager serving as a single management platform.  

With this improvement built on the Microsoft 365 Identity & Management fabric, we are looking to connect your security and IT teams with integrated experiences and eliminate the need to deploy and use additional tools and infrastructure to manage Microsoft Defender for Endpoint security settings.  

 

We’re releasing this new feature initially for Windows 10, Windows 11, Windows Server 2012R2 and above, and will gradually expand to support additional operating systems (including Linux and Mac OS).

Solution applies for any subscription that grants licenses for Microsoft Defender for Endpoint ( Plan 1 and Plan 2). 
Any subscription that grants Microsoft Defender for Endpoint licenses also grants your tenant access to the Endpoint security node of the Microsoft Endpoint Manager admin center. The Endpoint security node is where you'll configure and deploy policies to manage Microsoft Defender for Endpoint for your devices and monitor device status.

How does this work? 
The following diagram represents the new Microsoft Defender for Endpoint security configuration management solution.

 
 
 

This scenario requires organizations to enable security management in both the Microsoft Endpoint Manager and Microsoft Defender consoles.

When Microsoft Defender for Endpoint is deployed on a device (1), the client automatically and seamlessly registers the device to Azure Active Directory (either through your existing Hybrid process or directly with Azure for workgroup devices) (2).

Devices that are not enrolled with Endpoint Manager will now automatically be enrolled without the need to deploy and use additional tools and infrastructure (like Intune Enrollment) (3)

Changes will not apply for devices that are already enrolled in Microsoft Endpoint Manager devices enrolled into Intune will continue to receive policies through their established management channel. 

This new communication channel enables the device to be targeted to receive security management policies just like any other device (4). You can go ahead and use Azure Active Directory groups to target policies, and the devices use their membership in the groups to determine what policies they need to apply.

How to get started?

For detailed information on this scenario, please visit our documentation.

 

As always, we welcome your feedback and are looking forward to hearing it! 

Updated Dec 04, 2021
Version 3.0

19 Comments

  • Karl-WE  all windows servers can be onboarded to MEM, just not Serer Core. 
    The license for managing security setting included in all defender plans. 

  • Efrat Kliger that's great news! 

     

    Have some questions:

     

    I read in the docs that Windows Server Core installation does not support Azure AD join due to missing dsregcmd.

     

    So I wonder how Windows Servers can be onboarded. Usually would like to onboard them to Defender for Endpoint using Azure Arc / Azure security in Windows Admin Center.

     

    Will Windows Server appear in Endpoint Manager?

    Maybe I have overlooked it, how to join this public preview? 

     

    How about licensing for Endpoint Manager? Is it included in Defender Plans?

     

  • Security-guy's avatar
    Security-guy
    Copper Contributor

    Thank you, this is great. 

    Are the asr rules on the roadmap? Policy merge especially to make them more flexible? They are really hard to manage on sccm. 

    can tenant attach be used to “turn off” management by sccm if the rule is enforced from intune to stop conflicts?  This will help for migration scenarios. 

  • giladkeidar We recommend having a single authority managing device security settings to avoid conflicts and race conditions. We do not enforce a single authority with WS1 (or any other MDM besides the Intune), so you will still be able to manage the security setting via MEM. Make sure you are not managing the same set twice.  

     

    You can send me a message with your email to be included in the Linux preview once available (tentative ETA first half of 2022). 

  • Andrew_Woo  Since we added the tag scoping recently we recommend private preview customers turn off the feature, tag the device with MDE-Management and then turn it on again.
    Please make sure you follow all the prereq and steps specified here.
    You should be able to see if the device has any errors enrolling to MEM in the 'Managed by' column in the device inventory. 
    To troubleshoot, see Troubleshoot onboarding issues related to Security Management for Microsoft Defender for Endpoint. In case you still experience issues you may contact our support channels.

  • LoicM's avatar
    LoicM
    Brass Contributor

    Could you clarify if this feature is GA or a Public Preview?

    Thank you

  • giladkeidar's avatar
    giladkeidar
    Brass Contributor

    Efrat Kliger 

     

    1. If device is already managed by other MDM solution like WS1, will I still be able to manage MDE with MEM? Or this consider a MDM authority, as with full Intune device enrollment. 
    2. any ETA for Linux? (We are in the middle of big deployment 2000+ servers and. wondering which deployment tool to use). 

  • Andrew_Woo's avatar
    Andrew_Woo
    Iron Contributor

    How about those already enrolled before this and who did not show in the endpoint manager?

    How to make it appear in the endpoint manager?

    Have to offboard and onboard again?