Additional Microsoft Defender tools and services that provide security across various platforms and environments
For Intune-enrolled devices, the missing step is typically onboarding the devices to Microsoft Defender for Endpoint. Connecting Intune to Defender and deploying EDR-related policies does not by itself onboard devices into Defender.
The supported flow for Intune-enrolled devices is:
- Establish the Intune–Defender service-to-service connection.
- Onboard devices to Microsoft Defender for Endpoint using Intune policy.
- Create a device compliance policy to set acceptable device risk.
- Configure Conditional Access if access control based on risk is required.
If the goal is to see already Intune-enrolled devices in Defender, focus on step 2: Onboard devices with Microsoft Defender for Endpoint using Intune policy. Without onboarding, devices will not appear in Defender for monitoring.
A separate path exists for devices that are not enrolled in Intune: use security management for Microsoft Defender for Endpoint. In that model:
- Devices onboard to Microsoft Defender for Endpoint first.
- Devices then communicate with Intune to receive endpoint security policies.
- In the Microsoft Defender portal, Managed by should show MDE.
- In the Intune admin center All devices page, Managed by should also show MDE.
- MDE Enrollment status should display Success.
For tenant configuration of Defender security settings management, in the Microsoft Defender portal go to: Settings > Endpoints > Configuration Management > Enforcement Scope
For initial validation, Microsoft recommends:
- enabling platforms for security settings management,
- starting with On tagged devices,
- tagging test devices with
MDE-Management, - then validating enrollment.
Expected timing:
- Most devices complete enrollment and apply assigned policy within a few minutes.
- Some devices can take up to 24 hours.
Validation points:
- In the Microsoft Defender portal device inventory, Managed by should be MDE.
- On the device page or side panel, MDE Enrollment status should be Success.
- In Intune admin center > All devices, Managed by should display MDE.
If MDE Enrollment status is not Success, confirm the device is:
- updated, and
- in scope for security settings management based on the configured Enforcement Scope.
Also note that security settings management now supports devices that do not fully register in Microsoft Entra by using synthetic registration. Those devices can still onboard to Defender and receive security settings management policies.
So the key distinction is:
- Intune-enrolled devices: onboard them to Defender using Intune policy.
- Unenrolled devices: use Defender for Endpoint security settings management.
If the current deployment only enabled the connector, EDR settings, and syncs, but did not deploy the actual Defender for Endpoint onboarding policy, that explains why no devices are appearing in Defender.
References: