Microsoft Defender for Endpoint
Endpoint protection

Production Deployment

In brief

Updated section titles, anchors, wording, metadata, and publication date in the Microsoft Configuration Manager deployment guide.

What Defender admins need to know

Use the revised section names and anchors when navigating to or linking to deployment guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE side-by-side-scenarios]

This Defender for Endpoint deployment guide covers only deployments that use Microsoft Configuration Manager. Defender for Endpoint supports the use of other onboarding tools but we wonthis deployment guide doesn't cover those scenarios in the deployment guide.onboarding-tool scenarios. For more information, see Identify Defender for Endpoint architecture and deployment method.

[!Include defender-endpoint-setup-guide.md]

  • In the Microsoft Azure portal, under Manage Microsoft Entra ID, select View. Then, under Manage, select Licenses.

Validate your Cloud ServiceSolution Provider validationsetup

If you're a Cloud Service Provider (CSP) partner managing a customer tenant, you can check which licenses are provisioned and verify their state through the Microsoft 365 admin center.

:::image type="content" source="media/atp-O365-admin-portal-customer.png" alt-text="The Office 365 admin portal" lightbox="media/atp-O365-admin-portal-customer.png":::

Tenant ConfigurationConfigure your tenant settings

To provision Defender for Endpoint in your tenant, follow these steps:

  • Under Assets, select Devices.
  • Under Endpoints, select an item, such as Dashboard or Endpoint security policies.

DataReview data center location requirements

Microsoft Defender for Endpoint stores and process data in the same location as used by Microsoft Defender XDR. If Microsoft Defender XDR hasn't been turned on yet, onboarding to Defender for Endpoint also turns on Defender XDR, and a new data center location is automatically selected based on the location of active Microsoft 365 security services. The selected data center location is shown onin the screen.Microsoft Defender portal.

Network configurationConfigure network access for deployment

Ensure devices can connect to the Defender for Endpoint cloud services. The use of a proxy is recommended. See the following articles to configure your network:

  1. Verify client connectivity to Microsoft Defender for Endpoint service URLs.

In environments that restrict outbound URL-based filtering, you might want to allow traffic to specific IP addresses. Not all services are accessible in this waythrough specific IP addresses, and you need to evaluate how to address this potential issue in your environment. For example, you might need to download updates to a central location and then distribute them. For more information, see Configure connectivity using static IP ranges.

Next steps

After you complete the environment setup described in this article,guide, proceed to assign the required roles and permissions:

[!div class="nextstepaction"] Step 2 - Assign roles and permissions