Forum Discussion
pozlu0
Jul 24, 2023Copper Contributor
Exlude a Computer for some hour from defender from endpoint
Hello I would like to know if there is a way to exclude defender for endpoint protection from a pc from a couple of hours. Kind regards
- Jul 24, 2023You can set the device to troubleshooting mode, this doesn't turn off any protections but it will allow local admin to turn them off. Or, you could offboard the device using the API and then onboard it again when you are finished.
jbmartin6
Jul 24, 2023Iron Contributor
This is not what 'Exclude' does in MDE. The function mainly centers around vulnerability management. See here: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/exclude-devices
Jul 24, 2023
I know this but the only excluding in MDE is that option that cover the vulnerability management and reports, because offboarding a device from MDE is not an excluding 🙂 it is removing the device completely from MDE and that's not his case.
- jbmartin6Jul 24, 2023Iron ContributorYes, the poster did not specify exactly what they meant by 'exclude'. But, questions about exclusions always involve excluding from security protections, not excluding from vulnerability management reports. At best you should have clarified this limitation instead of potentially wasting the poster's time and the time of anyone else who winds up here looking to answer the same question.