Does an Intune EDR Policy Auto-Onboard Devices to Defender for Endpoint?
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You create an endpoint detection and response (EDR) policy. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that an assigned Intune EDR policy onboards Windows devices to Defender for Endpoint by itself; the trap is believing that only the Defender for Endpoint connector in Intune can perform automatic onboarding.
When Microsoft Defender for Endpoint is integrated with Intune, an endpoint detection and response (EDR) policy is a supported way to push the Defender for Endpoint onboarding configuration so enrolled devices onboard automatically. This page confirms that creating an EDR policy does meet the stated goal.
Answering No on the assumption that onboarding must be enabled through the Microsoft Defender for Endpoint connector in Intune or configured manually in the Defender portal, when an assigned EDR policy already delivers the onboarding package to targeted devices.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Intune, the Endpoint security workload provides an Endpoint detection and response (EDR) policy type whose purpose is exactly what the scenario asks for: onboarding devices to Microsoft Defender for Endpoint. When you create such a policy for the Windows platform and assign it to a device group, Intune delivers the Defender for Endpoint onboarding package and configuration to those devices, so devices that enroll (or that already exist in the targeted group) are onboarded automatically without any manual script or portal step. Integration between Defender for Endpoint and Intune in an E5 subscription is already assumed by the scenario, so nothing else is required. Because the solution of creating an EDR policy satisfies the requirement of automatic onboarding at enrollment, the correct verdict is Yes.Why the Other Options Are Wrong
"No" is the only distractor and it fails because it treats the EDR policy as if it merely tuned detection and response settings on an already-onboarded device. In reality the Intune EDR policy profile is one of the official onboarding mechanisms for Windows devices, alongside the Defender for Endpoint connector's automatic onboarding toggle. The connector is an alternative route, not a prerequisite, so its absence does not invalidate the stated solution. Choosing No would only be correct if the solution omitted the assignment of the policy to a device group or used a policy type that cannot carry onboarding data.Community Comment Notes
KoenJas's comment essentially reproduces the scenario text rather than adding an argument. Preeb argued the opposite of the key, writing that "Creating an endpoint detection and response (EDR) policy alone does not ensure" onboarding and insisting the Defender portal and additional Intune configuration are needed — that overstates the requirement, since the EDR policy itself deploys the onboarding configuration. Krayzr concluded simply that the answer "would be yes", and the learner votes are unanimous for A, matching the analysis above.Official Reference
Exam Strategy
For "does this meet the goal" case items, evaluate only the effect of the single action named in the solution against the stated requirement. An Intune EDR policy supplies the Defender for Endpoint onboarding payload on its own, so do not add imaginary prerequisites such as configuring the Defender portal before answering Yes.
Frequently Asked Questions
Why is answering No tempting on this Intune EDR policy question?
Many learners believe automatic onboarding requires the Defender for Endpoint connector in Intune, but an assigned EDR policy also delivers the onboarding configuration to targeted devices.
Does the EDR policy onboard devices that are already enrolled in Intune?
Yes. The policy is assigned to a device group, so existing and newly enrolled Windows devices in that group receive the Defender for Endpoint onboarding settings.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →