How to make our Intune managed machines becoming "Compliant" again?

Woody Chiu at RASI 191 Reputation points
2023-05-25T12:23:49.62+00:00

I am managing 142 Windows 10/11 machines in our retail stores and they are all Azure AD joined. I am in the progress of rolling out the first batch of 10 machines. By default, we have a policy set up under Devices > Compliance Policies. See FIG 1.

FIG 1.

User's image

The settings inside the policy have been set up that way for almost a year, and machines have been deployed via Intune Autopilot fine and marked as "Complaint" green checkmark afterward. However, most of the devices were marked as "Noncompliant" red cross after I rolled out an Intune App (Malwarebytes workstation agent) yesterday.

See FIG 2.

FIG 2.

User's image

I am pretty sure that is due to some of the Microsoft Defender built-in services listed in the above images under "System Security" on Windows 10/11 getting disabled after the third-party antivirus agent like Malwarebytes was installed, and those services have been configured as "Require" in the Compliance Policy settings.

Please advise what would be the best practice in this situation. Should I just reconfigure all those services back to "Not Configured"? If yes, please be specific about which particular ones should be changed.

Besides, I know we do have a certain protection level of Microsoft 365 security licenses included for our Microsoft 365 licenses. We made a decision to install Malwarebytes on top of them because we have been having luck with protecting all our on-prem Windows servers and workstations. Would that be a waste you think? How to determine what exactly the level of Microsoft 365 security we have? When I look at our Microsoft 365 Security portal. See FIG 3.

FIG 3.

User's image

It appears there are tons of goodies and monitors that could help our insight into the security posture of our Microsoft 365. I don't want to waste them. Are the info and monitors in the portal continue to be valid and useful to us even though we have rolled out Malwarebytes agents?

Also, how do I determine what Microsoft 365 Security or Microsoft Defender 365 (whatever the term is appropriate) license we currently have? Where to check?

Thank you very much for your answers in advance!

Woody

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
143 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,649 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 45,486 Reputation points Microsoft Vendor
    2023-05-26T01:43:31.5533333+00:00

    @Woody Chiu at RASI, Thanks for pasting in Q&A. Based as I know, for the setting such as Antivirus, Antispyware: will check the compliance that are registered with Windows Security Center. For "Microsoft Defender Antimalware", it turns on the Microsoft Defender anti-malware service.

    https://learn.microsoft.com/en-us/mem/intune/protect/compliance-policy-create-windows

    From your description, it seems Microsoft Defender built-in services will be disabled after third-party antivirus agent like Malwarebytes was installed, IF so, the compliance policy will consider the device as not compliant. To fix the issue, I think we can click on one non-compliant device, choose "device Compliance", then click on the affected policy to see the detailed non-compliance setting. Then change these settings to not configure. After the device check in, check if the status changed.

    User's image

    User's image

    To check what subscription and license in your environment, you can go to Microsoft 365 admin center, ‘Services & Subscriptions’ section, you can find current Microsoft 365 services and the license type

    https://toolingant.com/how-to-check-microsoft-365-license/

    Note: Non-Microsoft link, just for your reference.

    I notice you have other questions with "Microsoft 365 security" and Microsoft Defender 365 which we are not familiar. You can contact Microsoft 365 or Microsoft Defender support in the following link to get more help.

    Microsoft 365 community

    https://answers.microsoft.com/en-us/msoffice/forum?sort=LastReplyDate&dir=Desc&tab=All&status=all&mod=&modAge=&advFil=&postedAfter=&postedBefore=&threadType=All&isFilterExpanded=false&page=1

    Microsoft Defender for Endpoint support

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Woody Chiu at RASI 191 Reputation points
    2023-05-30T17:49:23.1066667+00:00

    I talked to Malwarebytes. They said there should be a way to keep Microsoft Defender's Real-Time Protection active mode rather than passive mode which makes a machine become non-compliant in response to detecting a third-party AV agent installation in the system.

    Since Malwarebytes told me their scanning agent is smart to detect if Microsoft Defender is currently doing RTP and will avoid running RTP at the same, I want to keep Microsoft Defender active even with a Third-party AV agent like MWB is installed.

    Do you know where exactly in Mircosoft 365 Defender Admin portal where I can set the MD RTP to continue to be active even after a third-party AV agent is running in a machine?

    Thanks,

    Woody