Azure AD Registered Device Showing as vulnerable in Defender Portal (Security.microsoft.com)

Copper Contributor
Hi All 
We have some devices showing in our Defender Endpoints portal (Secuity.microsoft.com) that are not enrolled in our Intune environment. I am wondering
  1. Why is the device showing in the Defender portal? The device is Azure AD Registered but not MDM enroled.
  2. How do we remove the device from showing in this portal safely without removing it from Azure AD?
Thanks
1 Reply
I know normally Microsoft would reply only if there aren't any other replies in a given time, but this post is over a year old so I'm taking the liberty to reply and ruin any chance of them being helpful in using their product simply to ask, OP, did you ever resolve this issue?

Thanks heaps