Forum Discussion

53CU1t's avatar
53CU1t
Copper Contributor
Apr 22, 2022
Solved

Defender for Endpoint Onboardingprofile Conflicts

I have the problem that some newly installed clients do not onboard in Defender. The onboarding is done via the Intune. For this purpose, a device configuration profile was created and set in the Int...
  • Oktay Sari's avatar
    Apr 30, 2022

    53CU1t 

     

    Not sure where your conflict comes from.. What policies did you exactly configure and are there multiple policies?


    You can either deploy the onboarding package app or use the EDR policy.

    assuming the prerequisites are met, here's how I onboard devices:

    I use https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-security-edr-policy to onboard devices. The profiles include an onboarding package for Microsoft Defender for Endpoint

     

    • Defender for endpoint enabled and connected with Intune/MEM. Service to service sync is up and running.
    • MEM>Endpoint Security>Endpoint Detection and Response
    • Create Profile
      • Platform: Windows 10, Windows 11 and Windows Server
      • Profile: Endpoint Detection and response
    • Microsoft Defender for Endpoint client configuration package type
      --> Auto from connector
    • Sample Sharing and Telemetry as desired.

    This should do the trick. Here are the docs that can help you with the configuration.

    1. https://docs.microsoft.com/en-us/mem/intune/protect/advanced-threat-protection-configure
    2. https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-security-edr-policy

     

Resources