question

yy119-8239 avatar image
0 Votes"
yy119-8239 asked LuDaiMSFT-0289 commented

Correlate Devices between Intune and Defender for Endpoint Security Center

Hi all,

Is there any persistent identifier that maps a managedDevice entity from the graph API to a machine entity from the Defender for Endpoint Security Center API?

I've been digging through the docs but can't seem to find any way to correlate them besides using computer name, but that can be easily changed by the user, and Intune and Defender's security center update their device records asynchronously, which means there might be several hours in between where correlation is not possible.

Any help would be greatly appreciated, thanks!

windows-10-securitymem-intune-general
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

You are right their are related through the computer name, so would you mind elaborate your scenario in details like what you want to achieve and how it should be changed?

0 Votes 0 ·

@yy119-8239 From view of intune, it seems Azure AD device ID or intune device ID is unique. I'm not sure if we can correlate Devices between intune and Defender for Endpoint Security Center with device ID. It is suggested to open a case to get more accurate help. It is free. The following link describes how to open a case, we can refer to it:
https://docs.microsoft.com/en-us/mem/intune/fundamentals/get-support

Hope this issue will be solved as soon as possible.

0 Votes 0 ·

0 Answers