question

AbrahamSony-2706 avatar image
0 Votes"
AbrahamSony-2706 asked AbrahamSony-2706 commented

Enrolled devices are not getting Assigned

I did a manual (Script method) enrollment of two devices ( Win 10 & Win 2019) and they are seen as enrolled in Defender 365 portal. However I don't see it as assigned in EDR, Antivirus, Attack Surface reduction etc. Please see attached screen shots.182370-endpoint-enrollement-ss.pdf


mem-intune-generalmem-intune-device-configurationsmem-intune-enrollment
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RahulJindal-2267 avatar image
0 Votes"
RahulJindal-2267 answered AbrahamSony-2706 commented

At the moment the feature set is limited if your devices are not enrolled into Intune. However, if you are planning to use AV, FW, EDR, then you can definitely consider using the MDE security configuration preview feature.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Will give it a try once I get a better grip on Intune. Thanks Rahul.

0 Votes 0 ·
RahulJindal-2267 avatar image
0 Votes"
RahulJindal-2267 answered RahulJindal-2267 commented

What profiles are you using for the policies? Servers cannot be managed using Intune unless they are tenant attached or you using the preview EP security settings.

· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks Rahul for the revert.

I am using "Windows 10 and later" and that could be the reason. However the group that I have assigned has a Win 10 Pro and a Win 2019 server. Will try to make separate groups and separate policies and update.

0 Votes 0 ·

Are the Windows 10 devices reporting onboarded under the AV report? Also, not all ASR rules will be supported on Windows 10 Pro. The requirements are listed here in the official link.enable-attack-surface-reduction


Also, did you configure the connector? Here are the details.advanced-threat-protection-configure


0 Votes 0 ·

I had already connected Intune using the same article you mentioned. I have now created two groups one for Win 10 and and one for Servers and created two profiles a) "Win 10 and Later" b) "Win 10, Win 11, and Win Server (Preview)" and assigned to the respective groups.

I still have the same results. I see both my devices in the devices bade in MS 365 Defender portal but in Endpoint admin center, I don't see the either of the devices.

Should I enable Automatic Enrollment in EPM? Note that I had run the script on both the machines and it completed successfully.


BTW:- I have not created any profiles in the Configuration Profiles blade under EPM Devices. The profiles that I was referring to earlier are created under EDR, AV, Attack Surface Reduction etc under respective Endpoint Security Blade, Manage Blade.

0 Votes 0 ·
Show more comments
AbrahamSony-2706 avatar image
0 Votes"
AbrahamSony-2706 answered

My Win 10 device is AAD joined (enabled at the time of creation). I Don't see it registered in Intune (EPM Admin Center) whereas it is registered in Defender (Device Inventory).

My interest at the moment is to test out the EDR followed by other EPM solutions such as AV, Attack Surface Reduction etc. I have never worked with Intune before and new to EPM as well. I connected Intune only because the onboarding document said so. i.e. Intune is NOT my primary goal now. Technically, my situation is close to the article you shared

'mde-security-integration" This article also says that if I don't integrate with Intune I don't get most of the features so I guess that is the best route. I think I need to get a grip on Intune first before I spent more time on this. Bit frustrated that to get a EDR working, it is a lot of learning curve. Appreciate if you can point to some good links.

Thanks for you help

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.