No. If the workload is switched for a device but there is no Intune enforced policy for Windows Defender, then the ConfigMgr agent will continue to enforce the assigned Defender policy from ConfigMgr. From memory, you'll be able to see evidence of this in the comanagementhandler.log.
Endpoint Protection workload - co-management
Hi, if I switch device configuration workload which also switches endpoint protection workload from CM to Intune what will happen with antimalware policies deployed to collections containing Windows 10 devices if I do not create them from scratch and deploy from Intune end? Basically would I be forced to create same antimalware policy on Intune end if the one on CM end would not be enforced on clients anymore?
Microsoft Security | Intune | Configuration Manager | Other
5 answers
Sort by: Most helpful
-
Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
2022-04-28T15:57:21.257+00:00 -
Amandayou-MSFT 11,156 Reputation points
2022-05-02T05:58:57.507+00:00 Hi @Bojan Zivkovic ,
Haven't heard from you for some time, is Jason's answer helpful to you? If it is helpful, please accept answer. It will make someone who has the similar issue easily find the answer.
If you have any other issues, please don't hesitate to let us know.
Thanks and have a nice day.
If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. -
Bojan Zivkovic 606 Reputation points
2022-05-02T10:40:58.427+00:00 In case of conflict I guess Intune end will take precedence (if managing workload)? What about settings not conflicting with each other (for instance something defined in MECM but not in Intune - will they merge)?
-
Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
2022-05-09T17:18:29.497+00:00 In case of conflict I guess Intune end will take precedence
If the workload is set to Intune, yes, Intune will win -- that's the point of the workload slider.
will they merge
No, never, As noted, that's the entire point of an admin configurable workload using the sliders.
-
Bojan Zivkovic 606 Reputation points
2022-05-16T10:52:54.23+00:00 Since I am mostly concerned here about devices being outside the LAN most of the time, is implementing CMG waste of time and money for companies having Intune too? What I do not really like in Intune is handling 3rd party apps updates (we use Patch My PC Publishing Service internally and it works fine with MECM) but having CMG just for 3rd party apps updates looks like overkill. We have strong emphasis on security so having OS and apps up to date is top priority.