Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is managing Microsoft Defender for Endpoint. The organization's security policy dictates that all unmanaged devices attempting to connect to the corporate network must be identified and blocked from accessing sensitive resources until they are properly onboarded and compliant. Which Defender for Endpoint capability, when integrated with network access control solutions, is primarily responsible for discovering these unmanaged devices?

  1. AAttack Surface Reduction
  2. BAutomated investigation and remediation
  3. CDevice discovery
  4. DEndpoint Detection and Response (EDR)
Show answer & explanation

Correct answer: C. Device discovery

Device discovery in Microsoft Defender for Endpoint actively finds unmanaged devices connected to the corporate network, providing visibility into potential security gaps and enabling integration with network access control solutions to block non-compliant devices.

Why the other options are wrong

  • A. Attack Surface Reduction rules prevent specific behaviors on managed devices, not discover unmanaged ones.
  • B. Automated investigation and remediation automatically responds to alerts on managed devices, not discovers unmanaged ones.
  • D. EDR focuses on detecting and responding to threats on already onboarded endpoints, not discovering unmanaged devices.

Defender for Endpoint Device Discovery

Device discovery in Microsoft Defender for Endpoint is a capability that uses onboarded endpoints to passively scan the network and actively probe for unmanaged devices, providing a comprehensive inventory of all network-connected assets, both managed and unmanaged.

  • Identifies unmanaged devices on the network.
  • Uses existing onboarded devices as sensors.
  • Provides asset inventory and security recommendations.
  • Enables integration with network access control.

Memory trick: Managing devices means discovering them, reducing attack surface, and responding to threats.

More Implement and manage Microsoft Defender XDR questions