Microsoft Defender for Endpoint
Endpoint protection

Configure Device Discovery

In brief

The page updates wording for customizing standard discovery and monitoring networks, and adds a direct link to the Monitored networks section for the advanced hunting query.

What Defender admins need to know

Administrators can find the relevant monitored-network guidance and query context more easily when managing device discovery.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.collection:

  • m365-security
  • tier1 ms.custom: admindeeplinkDEFENDER, msecd-doc-authoring-10141016 ms.topic: how-to ms.date: 06/17/07/02/2026 appliesto:
    • Microsoft Defender for Endpoint Plan 2

Control which devices perform standard discovery

ToYou can customize the list of devices used to perform standard discovery, do onediscovery in either of the following:these ways:

  • Enable standard discovery on all onboarded devices that support device discovery.
  • Select a subset or subsets of your devices using device tags (see Set up device discovery). When you select subsets of devices using device tags, all other devices run basic discovery only.

Manage monitored networks

You might want to monitor a network, for example, if you have a new corporate office or a remote site that needsyou want to be monitored.include in device discovery. For more information, see Monitored networks.

To manage monitored networks, in the device discovery settings, select Monitored networks, select the three dots next to a name of a network, and select one of the following options.

Explore devices in the network

You can use the following advanced hunting query to get more context about each network name describedshown in the Monitored networksMonitored networks list. The query lists all the onboarded devices that were connected to a certain network within the last seven days.

DeviceNetworkInfo