Configuration ordering

andywal tsa 1 Reputation point
2020-08-13T15:31:04.02+00:00

Apologies if this has been asked already. We have recently started to use Endpoint manager to deploy Defender. This is working grate. However i am a little confused which order i should be applying settings.
I can see the same settings in various locations. Should i be using configuration profiles or should i be using the settings under endpoint security?

For example. I can turn off Anti Tamper in an Endpoint protection profile or i can create a Windows security experience config under Enpoint security |Antivirus.
Any advice on the correct way/order to do this kind of thing?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,781 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-08-13T19:54:30.19+00:00

    The blog at https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/unified-endpoint-security-using-microsoft-endpoint-manager/ba-p/1417736 covers this.

    Basically, there is no correct way other than not configuring it in both places as this may create a conflict and may be difficult to troubleshoot. In general, the security baselines are easier to work with and should be preferred but they don't necessarily contain every setting so can be supplemented as or if needed by configuration profiles.

    There's a also a (longer) video at https://www.youtube.com/watch?v=f4klwWewXe0 that covers this as well.

    0 comments No comments