@Chad Miars, Thanks for posting in Q&A. From your description, we understand that you have confusion on using Intune or Microsoft 365 Defender Endpoint portal to manage security settings for Windows Endpoints.
We did some research. For the "Endpoint Security" section to manage security settings for devices enrolled in Intune generally. This is where you'll set up device security policies and settings that are tailored to the devices you're managing with Intune.
- Antivirus
- Attack surface reduction
- Endpoint detection and response
- Firewall
- Firewall Rules
For more information about Microsoft Defender for Microsoft Intune, please visit the link below:
The "Configuration Management" section under Microsoft 365 Defender is more focused on security configurations that are tied to threat detection and response, and it might be more relevant for endpoints that are not directly managed by Intune, such as servers or devices that fall outside of your Intune management scope. Here are some security settings you can configure:
- Incidents & alerts
- Hunting
- Action & submissions
- Threat analytics
- Secure score
- Learning hub
- Trials
- Partner catalog
For more information about Microsoft Defender for Endpoint, please visit the link below:
Microsoft 365 Defender portal | Microsoft Learn
To determine where we configure the policy, you can check which the device is managed by. If the device is managed by MDE, you can set the policy only in Microsoft Defender for endpoint to avoid conflict.
Hope above can be helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.