With Microsoft Endpoint I want to push Microsoft Defender permissions and other requirements with app configuration policies, but how to do this without user input?

Jesse ten Hoeve 0 Reputation points
2023-08-10T10:02:30.9433333+00:00

When enrolling new phones, users have to setup Defender manually:

1 Log in with domain account.

2 Accept Defender's terms.

3 Begin Android permissions bits...

4 Turn on All Files Access permission.

5 Accept VPN connection set up request [this is the only step I've found a possible zero-touch solution for online].

6 Turn on Appear On Top permission.

7 Agree to Accessibility services.

8 Accessibility > Installed Apps > Microsoft Defender > Turn this on > Then tap Allow.

9 Allow 'Stop optimising battery usage' for Defender.

10 Phone is then protected.

See this Reddit post: Microsoft Defender for Endpoint on Android - Intune Deployment. : r/sysadmin (reddit.com)

I can't believe that there isn't a solution for this. How am i supposed to roll this out to thousend of users?

I hope there is a solution.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,509 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,060 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,570 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,806 Reputation points Microsoft External Staff
    2023-08-11T01:50:03.4233333+00:00

    @Jesse ten Hoeve, Thanks for posting in Q&A. For your request, you can feedback to Microsoft 365 Defender to see if the new feature can be added in the future.

    https://feedbackportal.microsoft.com/feedback/forum/d7dd1275-f65e-ed11-9562-000d3a4e3f39


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.