Edit

Onboard Windows devices to Microsoft Defender for Endpoint with Configuration Manager

You can use Microsoft Configuration Manager current branch to onboard and monitor supported Windows client and Windows Server devices in Microsoft Defender for Endpoint. The Configuration Manager documentation contains the detailed console procedures. This article provides Defender-specific package selections, verification guidance, and offboarding behavior.

You can also use tenant attach to manage endpoint security policies from the Microsoft Intune admin center. For the complete Configuration Manager onboarding procedure, see Onboard devices using Configuration Manager.

Note

Defender for Endpoint doesn't support onboarding during the Out-of-Box Experience (OOBE) phase. Complete OOBE after installing or upgrading Windows before you onboard the device.

Note

The Defender deployment tool can be used to deploy Defender endpoint security on Windows and Linux devices. The tool is a lightweight, self-updating application that streamlines the deployment process. For more information, see Deploy Microsoft Defender endpoint security to Windows devices using the Defender deployment tool and Deploy Microsoft Defender endpoint security to Linux devices using the Defender deployment tool (preview).

Prerequisites

Onboard devices using Configuration Manager

Configuration Manager version 2207 and later can deploy the modern unified Defender for Endpoint client to Windows Server 2012 R2 and Windows Server 2016. For prerequisites and the complete onboarding procedure, see Onboard devices using Configuration Manager 2207 and later.

Select a device collection

Deploy the onboarding policy to an existing device collection, or create a limited collection for testing. Don't use a fixed operating-system build query unless the query accurately represents every supported operating system that you intend to onboard. For current collection guidance, see Create collections in Configuration Manager.

Download the onboarding package

On the Onboarding page in the Microsoft Defender portal at https://security.microsoft.com/securitysettings/endpoints/onboarding, select these values:

  • Step 1: Select an operating system to start deployment: Select Windows 10 and 11. The downloaded configuration file is also used for supported up-level Windows Server operating systems. Don't select Windows, which starts the separate Defender deployment tool workflow.
  • Deployment method: Select Microsoft Endpoint Configuration Manager current branch and later.

For the complete download procedure, see Get an onboarding configuration file for up-level devices.

Important

The Defender for Endpoint configuration file contains organization-specific information. Store and transfer the file securely.

Create and deploy the onboarding policy

Create the onboarding policy from the downloaded configuration file, and deploy the policy to the target device collection. For the complete procedure, see Onboard the up-level devices using Configuration Manager. The Configuration Manager console retains the legacy labels Microsoft Defender ATP Policies and Create Microsoft Defender ATP Policy.

Note

For Windows Server 2012 R2 and Windows Server 2016, select MDE Client (recommended) in the Configuration Manager client settings. For mixed collections that include devices that still require Microsoft Monitoring Agent (MMA), see Onboard devices with MDE Client and MMA. To migrate servers from MMA, see Migrate servers to the unified solution.

Configure sample collection

The onboarding policy wizard lets you choose None or All file types for sample sharing. You can also use a remediating Configuration Manager compliance rule to configure the sample collection registry value on targeted devices.

Note

Configuration Manager typically manages sample collection through the onboarding policy wizard or a compliance rule.

The compliance rule can configure this registry entry:

Path: "HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection"
Name: "AllowSampleCollection"
Value: 0 or 1

The key type is DWORD. Supported values are:

  • 0: Don't allow sample sharing from the device.
  • 1: Allow all file types to be shared from the device.

If the registry value doesn't exist, the default value is 1.

For current compliance-setting guidance, see Plan for and configure compliance settings.

Configure endpoint protection settings

Onboarding doesn't configure Microsoft Defender Antivirus or other endpoint protection features. Use Configuration Manager policies or tenant attach to configure the security controls required by your organization.

Important

Install the Endpoint Protection point site system role before you configure Configuration Manager client settings for Endpoint Protection.

Configure network protection

Configure network protection by using a Windows Defender Exploit Guard policy. Test network protection in audit mode before you enable block mode. For prerequisites and deployment instructions, see Configure network protection in Microsoft Configuration Manager.

Configure controlled folder access

Test controlled folder access in audit mode before you enable block mode. Review audit events and add trusted applications only when needed. For more information, see Configure controlled folder access and Monitor controlled folder access activity.

Monitor device configuration

Use the built-in Configuration Manager dashboard to review onboarding status and agent health. For the dashboard procedure and status definitions, see Monitor Microsoft Defender for Endpoint onboarding.

On the Device inventory page in the Microsoft Defender portal at https://security.microsoft.com/machines?category=all-devices, search for the target devices and verify that their sensor health state is active.

You can also use a non-remediating compliance rule to monitor this registry entry:

Path: "HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status"
Name: "OnboardingState"
Value: "1"

If deployment fails or a device doesn't report as expected, see Troubleshoot Microsoft Defender for Endpoint onboarding issues.

Run a detection test to verify onboarding

To generate a test alert and confirm end-to-end reporting, see Run a detection test on a newly onboarded device.

Offboard devices using Configuration Manager

For Configuration Manager current branch, the offboarding configuration file expires 30 days after you download it. Defender for Endpoint rejects expired files.

Important

The Defender for Endpoint offboarding configuration file contains organization-specific information. Store and transfer the file securely.

Don't deploy onboarding and offboarding policies to the same device at the same time. Remove the target devices from the onboarding policy deployment before you deploy the offboarding policy.

Offboard devices using Microsoft Configuration Manager current branch

On the Offboarding page in the Microsoft Defender portal at https://security.microsoft.com/securitysettings/endpoints/offboarding, select Windows 10 and 11 and Microsoft Endpoint Configuration Manager current branch and later. The Windows 10 and 11 package also offboards supported Windows Server devices in the collection and removes MMA when needed. Don't select Windows, which starts the separate Defender deployment tool workflow.

For instructions to create and deploy the Configuration Manager offboarding policy, see Create an offboarding configuration file.

Important

Offboarding stops the device from sending new detection, vulnerability, and security data to Defender for Endpoint. Historical data remains in the Defender portal until the configured retention period expires. The device profile, without data, remains in the device inventory for up to 180 days. For more information, see Offboard devices.

Offboard devices using System Center 2012 R2 Configuration Manager

System Center 2012 and System Center 2012 R2 reached end of support on July 12, 2022. Upgrade to Configuration Manager current branch before you deploy or manage Defender for Endpoint. For more information, see System Center 2012 end of support.

The following archived documentation remains available for organizations completing a migration: