Microsoft Defender for Endpoint Plan 1 without intune, application control available?

Joe Kwok 1 Reputation point
2022-09-02T04:15:49.593+00:00

Hi all,

I am quite confused on Microsoft license.
If I would apply Attack surface reduction such as application control, only Microsoft Defender for Endpoint Plan 1 without Intune is it available?

Since I found that the link as below mention that MDE Plan 1 include Attack surface reduction
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/defender-endpoint-plan-1

But I also found that the link as below mention Attack surface reduction required Microsoft Endpoint Manager, not support by MDE Security configuration
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/security-config-management

And I found the deployment guide, it can be use Intune to deploy.
https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-deployment-guide

So, what is the license I need to have? Is it means that I can deploy via script if I only have MDE Plan 1 without Intune?

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
882 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,406 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 43,721 Reputation points Microsoft Vendor
    2022-09-02T06:28:28.363+00:00

    @Joe Kwok , For Intune, it is a cloud service and can help deploy the policy to devices . Like the policies under Attack surface reduction. If you have other methods to deploy the policy setting like script. I think you can work without Intune.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.