How to Force MDE device management ( instead of configuration manager) for Windows Server

Agnieszka 21 Reputation points
2023-11-21T13:05:08.2566667+00:00

Hi, We are trying to managed Windows server 2016 and 2019 using the MDE /Intune  policies. 
The status for Device managemnt  is showing the status managed by 'config mgr' ( should be changed to managed by MDE)

Settings for 'Use MDE to enforce security configuration settings from MEM' is enable and set up for 'on all devices' . 

Are you aware if there is anything what can still forcing configuration manager to manage it ?

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
399 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,486 Reputation points MVP
    2023-11-22T05:57:29.6433333+00:00

    You can only utilize Defender for Endpoint for Servers, the Intune as MDM solution is not supported for Servers.

    https://techcommunity.microsoft.com/t5/intune-customer-success/windows-server-devices-managed-by-defender-for-endpoint-now/ba-p/3767773

    0 comments No comments

  2. ZhoumingDuan-MSFT 11,990 Reputation points Microsoft Vendor
    2023-11-22T06:32:48.38+00:00

    @A3193,Thanks for posting in Q&A.

    From your description, I know that you want to know if there is other way to force configuration manager to manage device.

    Based on my research, Windows Server is not the supported operating system in Intune, but you can use Intune to manage MDE security settings on devices not enrolled with Intune. It allows you to configure policies for endpoint security for MDE and assign them to Microsoft Entra ID groups. And the status for Device management will be MDE.

    However, if you are planning to use Configuration Manager, you can set the toggle for Manage Security settings using Configuration Manager to On. Then the device Management status will be "config mgr" and you can use Configuration manager to manage the targeted device.

    Here are some related documents you can refer.

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/switch-to-mde-phase-2?view=o365-worldwide#step-2-configure-defender-for-endpoint-plan-1-or-plan-2

    https://video2.skills-academy.com/en-us/mem/intune/protect/mde-security-integration#co-existence-with-microsoft-endpoint-configuration-manager

    Hope this can be help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.