Additional Microsoft Defender tools and services that provide security across various platforms and environments
Dear @Purna Durgarao Sugandhapu
There are now two supported methods to automate assignment of the MDE-Management tag.
The first is Dynamic Asset Rules in the Microsoft Defender portal. These rules can automatically assign the tag based on device attributes, making them a good fit for larger environments where newly onboarded servers should be included without manual intervention.
The second option is registry-based tagging on Windows servers by configuring the supported DeviceTagging policy and setting the Group value to MDE-Management. This approach is particularly useful if registry settings are already being deployed through Group Policy, Configuration Manager, or another configuration management solution.
For Security Settings Management, Microsoft continues to recommend enabling the enforcement scope for On tagged devices and using the MDE-Management tag to target an initial pilot group. Once you've confirmed that policies are being applied as expected, you can gradually expand the deployment by automating tag assignment through either of the supported methods.
Microsoft offical guide: Create and manage device tags and target devices
If this answers your query, please click Accept Answer and Upvote if you found it helpful. If you have any further questions, feel free to let us know.