Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A company is onboarding 5,000 new Windows 11 devices to Microsoft Defender for Endpoint. The security team requires that these devices are onboarded using a method that is scalable, automated, and integrates seamlessly with their existing Microsoft Intune environment for device management. Which onboarding method should the administrator choose?
- ALocal script (GPO or SCCM)
- BDevice Management APIs
- CMicrosoft Intune
- DPowerShell script (manual execution)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Intune
Microsoft Intune offers a highly scalable and automated method for onboarding devices to Defender for Endpoint, leveraging existing device management infrastructure to deploy the onboarding package to a large number of Windows 11 devices seamlessly.
Why the other options are wrong
- A. While GPO/SCCM can be automated, Intune is specifically designed for modern cloud-based management and provides a more seamless integration for Windows 11 in a cloud-first environment.
- B. Device Management APIs are for custom integrations and scripting, not a direct onboarding method for this scale and existing Intune environment.
- D. Manual PowerShell script execution is not scalable or automated for 5,000 devices.
Defender for Endpoint Onboarding Methods
Microsoft Defender for Endpoint supports various methods for onboarding devices, including Group Policy, Microsoft Endpoint Configuration Manager (SCCM), local script, and Microsoft Intune, to accommodate different organizational needs and infrastructures.
- Intune is ideal for modern, cloud-managed devices.
- GPO/SCCM for on-premises/hybrid environments.
- Local script for small scale or testing.
- APIs for custom, advanced deployments.
Memory trick: Onboarding devices needs to be scalable, automated, and fit existing management.