Forum Discussion
MDE endpoint to Purview onboarding
The important distinction is device onboarding versus DLP policy enforcement. Microsoft documents shared onboarding between Defender for Endpoint and Purview, so your existing MDE devices do not need a second onboarding package. Do not treat the tenant monitoring switch as a way to onboard only a few of those devices. For a controlled DLP pilot, create a policy whose Devices location targets specific devices or device groups, and begin in simulation mode. Review the Always audit file activity setting and any other Purview monitoring configuration beforehand: having no DLP policies does not necessarily mean no activity collection. Your rollback plan should first disable the pilot policy and verify its effect. Avoid offboarding devices merely to undo the pilot, because onboarding is shared with MDE. If disabling tenant monitoring itself is required, obtain confirmation of the supported reversal and its effects from Microsoft before enabling it.