Restrict Defender ATP enrollment?

Fredrik Hofgren 1 Reputation point
2020-09-09T05:57:28.803+00:00

Greetings
I realize I've missed some change notification along the line because the Defender ATP enrollment workflow seems to have changed. We used to have a "Microsoft Defender ATP (Windows 10 Desktop)" configuration profile with the ATP enrollment package assigned to our Microsoft Enpoint Manager/Intune PCs with "Corporate" ownership only. This way we didn't push ATP to the employees who MEM enrolled their home PCs, we simply doesn't have a business case for that scenario.
We also have our Defender ATP connected to MEM but isn't using that for conditional access at the moment. When reading up on the changes it seems having this connection between ATP and MEM is all thats required for Defender ATP to enroll PCs and thus consume ATP licenses. This also includes the previously omitted personally enrolled PCs.

So, is there some way for me, in this new workflow, to restore my enrollment process and leave the personal PCs out? Or do I have to rethink my own workflow?

Regards
Fredrik

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,279 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AndyLiu-MSFT 586 Reputation points
    2020-09-10T01:10:41.613+00:00

    @Fredrik Hofgren

    Based on the scenario, your corporate plans to integrate Microsoft Defender ATP with Microsoft Intune as a Mobile Threat Defense solution. By using Conditional Access, only the marked compliant devices can be enrolled in Intune, or allowed to access the corporate resources.

    Please click the following link for more details about integrating Defender ATP with Intune.

    Enforce compliance for Microsoft Defender ATP with Conditional Access in Intune

    To allow the enrollment for home PC without consuming ATP license, you can exclude the home devices from the compliance policy in Intune, so that the home PCs will not be evaluated as non-compliance.

    You can create a dynamic device group based on the device ownership, in which the home PCs will be put into the group automatically. Then, exclude that group from the compliance policy. Please click the following links for more info about dynamic group and compliance policy.

    groups-dynamic-membership
    device-compliance-get-started

    There is another way for managing home PC. Instead of MDM enrollment, you can deploy the MAM policies for protecting the corporate data at the apps level.

    To learn more about Intune MAM, please click the following link.

    What is Microsoft Intune app management?


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments