Microsoft Defender for Endpoint
Endpoint protection

Set up Microsoft Defender for Endpoint during migration

In brief

The Phase 2 migration page was retitled, its date and metadata were updated, migration diagram labels were clarified, Step 3 was renamed to cover onboarding and protection settings, and a Group Policy link was corrected. Additional anchors and clearer exclusion wording were added.

What Defender admins need to know

Administrators following the migration guide get clearer navigation and more precise setup instructions; no configuration change is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Migrate to Microsoft Defender for Endpoint - Phase 2: Setup

Diagram of migration phase 1: prepare your environment for migration to Defender for Endpoint.
Phase 1: Prepare your environment
Diagram of migration phase 2: set up your Defender for Endpoint environment.
Phase 2: Set up
Diagram of migration phase 3: onboard devices to Microsoft Defender for Endpoint.
Phase 3: Onboard devices to Defender for Endpoint
You're here!

Step 3: Configure Defender for Endpoint onboarding and protection settings

Configure your Defender for Endpoint capabilities before devices are onboarded.

Screen What it means
:::image type="content" source="media/mde-hangon-provisioning.png" alt-text="Screenshot showing message that says hang on because MDE isn't provisioned yet." lightbox="media/mde-hangon-provisioning.png"::: Defender for Endpoint isn't finished provisioning yet. You might have to wait a little while for the process to finish.
:::image type="content" source="media/device-inventory-empty.png" alt-text="Screenshot showing device inventory page with no device onboarded yet." lightbox="media/device-inventory-empty.png"::: Defender for Endpoint is provisioned. In this case, proceed to the next step.step 2, Turn on tamper protection.
  1. Turn on tamper protection. We recommend turning tamper protection on for your whole organization. You can do this task in the Microsoft Defender portal.

    |---|---| |Intune|1. In the Intune admin center, select Devices > Configuration profiles, and then select the profile type you want to configure. If you haven't yet created a Device restrictions profile type, or if you want to create a new one, see Configure device restriction settings in Microsoft Intune.

    2. Select Properties, and then select Configuration settings: Edit

    3. Expand Microsoft Defender Antivirus.

    4. Enable Cloud-delivered protection.

    5. In the Prompt users before sample submission dropdown, select Send all samples automatically.

    6. In the Detect potentially unwanted applications dropdown, select Enable or Audit.

    7. Select Review + save, and then choose Save.

    TIP: For more information about Intune device profiles, including how to create and configure their settings, see What are Microsoft Intune device profiles?.| |Configuration Manager|See Create and deploy antimalware policies for Endpoint Protection in Configuration Manager.

    When you create and configure your antimalware policies, make sure to review the real-time protection settings and enable block at first sight. |Advanced Group Policy Management
    or
    Group Policy Management ConsoleGroup Policy Management Console|1. Go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus.

    2. Look for a policy called Turn off Microsoft Defender Antivirus.

    3. Choose Edit policy setting, and make sure that policy is disabled. Disabling that policy enables Microsoft Defender Antivirus. (You might see Windows Defender Antivirus instead of Microsoft Defender Antivirus in some versions of Windows.)| |Control Panel in Windows|Follow the guidance here: Company Portal device setting requirements for Windows. (You might see Windows Defender Antivirus instead of Microsoft Defender Antivirus in some versions of Windows.)|

    If you have Defender for Endpoint Plan 1, your initial setup and configuration is complete. If you have Defender for Endpoint Plan 2, continue through steps 6-7.

Learn more about exclusions for Microsoft Defender for Endpoint and Microsoft Defender Antivirus.

Keep the following points aboutImportant considerations for Microsoft Defender Antivirus exclusions in mind

When you add exclusions to Microsoft Defender Antivirus scans, you should add path and process exclusions.