Skip to content
Security & DefenderProject guide

Onboarding Devices to Defender for Business With Intune

Connect Defender and Intune, onboard Windows devices automatically, run Defender Antivirus in the right mode, and verify each device is actually protected, not just "onboarded".

Microsoft Defender for Business is included in Microsoft 365 Business Premium. It gives you endpoint detection and response (EDR), next-generation antivirus, and attack surface reduction, managed from the same portals you already use. It's one of the most valuable things in the license, and one of the most often left switched off.

This runbook covers onboarding Windows devices through Intune and checking that protection is actually working.

Defender for Business vs. Defender for Endpoint

Defender for BusinessDefender for Endpoint P2
Included inBusiness Premium (or standalone)Microsoft 365 E5 (or standalone)
Designed forUp to 300 usersEnterprises
EDR, AV, ASRYesYes
Advanced hunting, longer data retentionLimitedFull

The onboarding mechanics are the same, and both use the Defender (MDE) sensor built into Windows.

Step 1: Connect Intune and Defender

  1. In the Defender portal, go to Settings -> Endpoints -> Advanced features and turn on Microsoft Intune connection.
  2. In Intune, go to Endpoint security -> Microsoft Defender for Endpoint and turn on the connection for Windows (and other platforms you use).
  3. Wait for the connection status to show Enabled on the Intune side.

Step 2: Onboard with an EDR policy

Create an Endpoint security -> Endpoint detection and response policy for Windows and set the onboarding package to Auto from connector. Assign it to your device groups. Intune delivers the onboarding blob, and the built-in Defender sensor starts reporting.

Step 3: Antivirus in the right mode

If another antivirus product is still installed, Defender Antivirus drops into passive mode, so EDR still sees threats but Defender won't block them. Decide deliberately:

  • Replacing the old AV: deploy Defender policies first, confirm onboarding, then uninstall the old product. Defender switches to active mode.
  • Keeping the old AV: passive mode is expected, but make sure someone is watching both consoles.

Check the mode on a device:

powershell
Get-MpComputerStatus | Select-Object AMRunningMode, AntivirusEnabled, RealTimeProtectionEnabled, IsTamperProtected

AMRunningMode should be Normal for Defender as the primary antivirus.

Step 4: Turn on the protections that matter

  • Tamper protection, so malware (or a well-meaning user) can't turn Defender off
  • Cloud-delivered protection and automatic sample submission
  • Attack surface reduction (ASR) rules, starting in audit mode and moving to block after reviewing what they'd catch
  • Network protection, and web content filtering if you want category blocking

Step 5: Verify, don't assume

"Onboarded" in a portal isn't the same as "protected." Check both:

powershell
# The sensor service should be Running
Get-Service -Name Sense | Select-Object Status, StartType

# Onboarding state: 1 means onboarded
Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status" |
  Select-Object OnboardingState, LastConnected

Then, in the Defender portal:

  • The device appears in the Device inventory with a recent last seen time.
  • Sensor health is Active, not Inactive or Misconfigured.
  • Run Microsoft's harmless detection test from the onboarding page and confirm an alert appears.

Connect it to compliance

Once devices report to Defender, you can add Require the device to be at or under the machine risk score to your Intune compliance policy. Combined with Conditional Access, a compromised device loses access to company data automatically.

// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.