Defender for business policies

GeoffA 1 Reputation point
2022-05-13T06:54:55.323+00:00

we are about to implement Defender for Business but already use inTune, I'm not sure if I'm just over thinking things but we have some conditional access policies already setup in Endpoint manager, will these be affected if we use DfB as the management system, or should we continue to use Defender for Endpoint as the management system, hope all that makes sense

Thanks

Geoff

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Reza-Ameri 16,831 Reputation points
    2022-05-14T16:18:05.64+00:00

    Intune and Defender are not the same product and they complement each other. For example, consider Azure and Intune, they have policies and work together and it is not like replacing each other. You may use both alongside each other and together.


  2. GeoffA 1 Reputation point
    2022-05-18T07:21:08.26+00:00

    Hi, thanks for this, so would the conditional access policies be part of intune or endpoint manager? or would that be hard for you to be able to say? and does this actually make a difference, as when setting up DfB it states that you will need to disable any policies in DfE, and that is a scary thought, if we are then unable to setup the same or similar policies in DfB

    thanks

    0 comments No comments

  3. Oscar Molkenthin-Paredes 1 Reputation point
    2022-10-12T15:06:38.057+00:00

    Some important points

    • Policies are assigned to a priority order
    • Devices apply only the first policy
    • The order can be changed
    • Default policies get the lowest priority

    Example -> Next-Generation Protection:

    • AllowBehaviorMonitoring
    • AllowIOAVProtection
    • AllowScriptScanning

    Onboarding process

    • It is recommended to add the devices via Microsoft Intune before configuring Defender for Business.
    • If the devices are not provisioned through Intune, we still recommend that you complete this process on the Microsoft Endpoint Manager admin center before Defender is configured.
    • For very small companies (for example, up to 20 devices), a manual configuration with local scripts directly via the Defender makes sense. For mobile devices or for companies with more users, it is recommended that you perform the onboarding process with Intune.
    0 comments No comments