Microsoft Defender for Endpoint
Endpoint protection

Manage tamper protection using tenant attach with Configuration Manager, version 2006

In brief

The article date and authoring metadata were updated, terminology was refined to “tamper-protected security settings,” and the additional-information section heading was shortened.

What Defender admins need to know

Administrators may see updated terminology and page metadata when consulting this guidance; no action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Turn tamper protection on or off using tenant attach with Configuration Manager. ms.service: defender-endpoint ms.localizationpriority: medium ms.date: 06/16/07/03/2026 ms.topic: how-to author: limwainstein ms.author: lwainstein ms.custom:

  • msecd-doc-authoring-10141016
  • nextgen
  • admindeeplinkDEFENDER ms.subservice: ngp

Manage tamper protection using tenant attach with Configuration Manager, version 2006

Tamper protection helps protect certain tamper-protected security settings, such as virus and threat protection, from being disabled or changed. If you're part of your organization's security team, and you're using version 2006 of Configuration Manager, you can manage the tamper protection feature for devices by using a method called tenant attach. Tenant attach enables you to sync your on-premises-only Configuration Manager devices into the Intune admin center, and then deliver endpoint security configuration policies to on-premises collections & devices.

Using Configuration Manager with tenant attach, you can turn on (or off) the tamper protection feature for some or all devices.

Related content

The following resources provideLearn more information about tamper protection: