Microsoft Defender for Endpoint
Architecture and deployment

Onboard Windows devices to Microsoft Defender for Endpoint by using Microsoft Intune

In brief

The documentation now describes onboarding and offboarding Windows 10 and Windows 11 devices with Intune, adds Intune licensing and Endpoint Security Manager prerequisites, updates links, and notes that diagnostic reporting frequency is deprecated in Intune EDR policies.

What Defender admins need to know

Review the updated prerequisites, permissions, licensing, and policy guidance when deploying or managing Defender for Endpoint through Intune.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboard Windows devices to Microsoft Defender for Endpoint by using Microsoft Intune

[!INCLUDE Microsoft Defender deployment tool preview]

Use Microsoft Intune to onboard Windows 10 and Windows 11 devices to Microsoft Defender for Endpoint. Onboarding configures devices to communicate with Defender for Endpoint for threat detection and device risk assessment. You can also use Intune to offboard devices that no longer need monitoring.

Defender for Endpoint supports mobile device management (MDM) solutions to configure Windows 10 devices. Defender for Endpoint supports MDMs by providing OMA-URIs to create policies to manage devices.

configuration through Open Mobile Alliance Uniform Resource Identifier (OMA-URI) settings. For more information on using Defender for Endpoint CSP, see, WindowsAdvancedThreatProtection CSPinformation, see WindowsAdvancedThreatProtection CSP and WindowsAdvancedThreatProtection DDF fileWindowsAdvancedThreatProtection DDF file.

Before you begin

Devices must be enrolled with

  • Enroll the devices in Microsoft Intune as your Mobile Device Management (MDM)MDM solution.

    For more information on enabling MDMinformation, see Device enrollment in Microsoft Intune.

  • To create endpoint detection and response (EDR) policies, use an account with Microsoftthe Endpoint Security Manager role or equivalent permissions.

Intune is a separate product that's not included with every Defender for Endpoint subscription. You need a subscription that includes Intune, or you can buy Intune separately as a standalone subscription or add-on. For details, see Device enrollment (Microsoft Intune)Microsoft Intune licensing. If you don't have Intune, review the other methods in Identify Defender for Endpoint architecture and deployment method.

Onboard devices using Microsoft Intune

Check outReview Defender for Endpoint architecture and deployment methods to seeselect the various paths in deploying Defenderappropriate onboarding method for Endpoint.your environment.

Follow the instructions from Intune.

For more information on usingTo connect Intune to Defender for Endpoint CSP, see, WindowsAdvancedThreatProtection CSP and WindowsAdvancedThreatProtection DDF fileonboard devices, follow the instructions in Configure Microsoft Defender for Endpoint with Intune and onboard devices.

Run a detection test to verify onboarding

Offboard devices using Mobile Device Management tools

For security reasons, the package used to Offboardoffboard devices expires seven days after the date it was downloaded.you download it. Expired offboarding packages sent to a device are rejected. When downloadingyou download an offboarding package, you're notified of the package's expiryportal displays its expiration date, and the datewhich is also included in the package name.

  1. Get the offboarding package from the Defender portal.

    On the Offboarding page in the Defender portal at https://security.microsoft.com/securitysettings/endpoints/offboarding as follows:, configure the following settings:

    1. InAt the navigation pane,top of the page, selectSettings > Endpoints > Device management > Offboarding.

    2. Select Windows 10 orand Windows 11 as the operating system..

    3. In the Deployment methodOffboard a device field,section that appears, select Mobile Device Management / Microsoft Intune as the Deployment method.

    4. SelectAt the bottom of the page, select Download package, select Download in the confirmation dialog, and then save the .zip file.WindowsDefenderATPOffboardingPackage_valid_until_YYYY-MM-DD.offboarding.zip file in a location that's easy to find.

  2. Extract the contents of the .zip file (a file named WindowsDefenderATP_valid_until_YYYY-MM-DD.offboarding) to a shared, read-only location that can be accessed by's accessible to the network administratorsadmins who'll deploy are responsible for deploying the package. You should have a file named WindowsDefenderATP_valid_until_YYYY-MM-DD.offboarding.

  3. In the Microsoft Intune admin center, you canMicrosoft Intune admin center, use a custom configuration policy or an EDR policy.one of the following deployment methods:

    MethodProcedure
    • Custom configuration policy

    1. In the navigation pane, select Devices > By platform >: To create Windows > Manage Devices > Configurationdevice configuration policy, see Create a device configuration profile in Microsoft Intune (opens in a new tab in the Intune documentation).

    2. Under
    Policies select Create > New Policy.

    3. In
    When creating the policy, use these specific settings:
    • Create a profilePlatform slide out, select: Select Windows 10 and later as .
    • PlatformProfile type and: Select Templates as Profile Type.

      4. Under
    • Template Namename, select the: Select Custom template and select Create.

      5. Enter a value for
      Name and select Next.

      6. Under
    • Configuration settings, select tab: Add and use the following settings:
      • OMA-URI settings:
        - Name: Provide a name
        - OMA-URI:
        : Enter ./Device/Vendor/MSFT/WindowsAdvancedThreatProtection/Offboarding
        - Date type:
        .
      • Data type: Select String
        - Value: Copy
        .
      • Value: Paste the value from the content of the WindowsDefenderATP_valid_until_YYYY-MM-DD offboarding file.
  4. EDR policy: To create an Endpoint detection and response policy, see Deploy endpoint detection and response policy with Intune (opens in a new tab in the Intune documentation). When creating the policy, use these specific settings:

    • Platform: Select Windows.
    • Profile: Select Endpoint detection and response.
    • Configuration settings tab:
      • Microsoft Defender for Endpoint client configuration package type: Select Offboard.
      • In the Offboarding (Device) setting that appears, paste the value from the content of the WindowsDefenderATP_valid_until_YYYY-MM-DD offboarding file.

        7. Make the appropriate group assignments, applicability rules, and on the
        Review + create step, select Create.
  5. EDR policy1. In the navigation pane, select Endpoint security > Manage > Endpoint detection and response.

    2. Under
    Endpoint detection and response (EDR) policies, select Create policy.

    3. In the
    Create a profile slide out, select Windows as Platform and Endpoint detection and response and select Create.

    5. Enter a value for
    Name and select Next.

    6. Under
    Configuration settings, select Offboard for the setting Microsoft Defender for Endpoint client configuration package type.

    7. Copy the value from the content of the
    WindowsDefenderATP_valid_until_YYYY-MM-DD offboarding file and paste it in the Offboarding (Device) setting. Then select Next.

    8. Specify any scope tags if needed, make the appropriate group assignments and on the
    Review + create step, select Create.

    For more information on Microsoft Intune policy settings, see Windows 10 policy settings in Microsoft Intune.

Related content