Windows 11 devices are enrolled in Microsoft Intune, the organisation holds Microsoft Defender for Endpoint licences, and the security team can sign in to the Microsoft Defender portal. No enrolled device appears in the device inventory of the Defender portal, and the endpoint security node of the Microsoft Intune admin center reports the Microsoft Defender for Endpoint connection status as unavailable. You must have the enrolled Windows devices onboarded to Microsoft Defender for Endpoint from Intune. Select TWO actions.
- ATurn on the connection to Microsoft Intune in the advanced features of the Microsoft Defender portal, so that the service to service connection between the two services is established. Correct
- BCreate an endpoint detection and response policy in Intune that takes its client configuration package automatically from the connector, and assign it to a group holding those Windows devices. Correct
- CAssign a Windows compliance policy that requires the device to be at or under a stated machine risk score, so that Intune begins collecting a risk rating from Defender for Endpoint.
- DDeploy an endpoint security antivirus policy that turns on cloud delivered protection and real time protection for the same group of enrolled Windows 11 devices.
- ESwitch tamper protection on in the Windows security baseline, so that nothing running on the device can stop the Defender for Endpoint sensor from registering with the service.
Why A is correct: Correct. The connector is a two ended arrangement, and the Defender portal side of it has to be switched on before Intune can obtain onboarding configuration from Defender for Endpoint or receive device risk back from it.
Why B is correct: Correct. The endpoint detection and response policy is the vehicle that carries the onboarding configuration to an assigned device, and taking the package automatically from the connector avoids handling an exported onboarding file.
Why C is wrong: Tempting because that setting is genuinely part of the integration and does read a rating from Defender for Endpoint. It is wrong here because a compliance policy reports a state for a device that is already onboarded, and it onboards nothing itself.
Why D is wrong: Tempting because Microsoft Defender Antivirus and Defender for Endpoint work together on a Windows client. It is wrong because antivirus settings tune protection on a device, and the device still holds no sensor registration with the Defender for Endpoint service.
Why E is wrong: Tempting because tamper protection does defend the sensor once it is running. It is wrong because it protects settings that already exist, and a device that has never been onboarded has no sensor registration to protect.