Managing MS Defender for EndPoints from MECM

Copper Contributor

We onboarded several devices to Micosoft Defender for EndPoints P1 using MECM.   The onboarding was successful, but the devices are no longer are applying the Antimalware Policies from MECM.  Specifically, we disable Real Time Scanning since we're using Carbon Black cloud and don't want to manage two sets of products.

 

The documentation has my head spinning due to what seems like numerous ways to onboard devices and manage them.  Am I wrong in thinking that the EndPoint Protection policies specified in MECM would apply to Windows Defender?

2 Replies
Did you configure the EP site role and enable EP in client settings?
Yes, we've been managing Windows Defender with SCCM/MECM for a number of years. It's just the clients that I onboard with Defender for EndPoints that don't seem to be getting the policies.