Forum Discussion
kcr
Feb 27, 2025Copper Contributor
Assigning Microsoft Defender for Endpoint (DFE) Licenses to Devices Without a Cloud-Visible User
We have a number of Windows 10 and Windows 7 clients that are used to control production systems. These devices do not have a cloud-visible user, as they are not associated with an Entra ID (Azure AD...
ElliotRobinson
Mar 12, 2025Iron Contributor
Assigning Microsoft Defender for Endpoint (DFE) licenses to devices without a cloud-visible user, such as those not associated with an Entra ID (Azure AD) account, presents challenges due to DFE's primarily user-based licensing model. Here are some approaches to consider:
- Assign Licenses to Entra ID Users: DFE licenses are typically assigned to user identities within Entra ID. If your organization doesn't sync on-premises Active Directory (AD) to Entra ID, you may need to establish this synchronization to assign licenses appropriately.
- Onboard Devices Without Entra ID: It's possible to onboard devices to DFE even if they're not connected to AD or Entra ID. This involves deploying the Defender for Endpoint agent directly on the devices. However, without user association in Entra ID, managing licenses and policies becomes more complex.