Does Co-management Auto-Onboard Devices to Defender for Endpoint?

Implement and manage endpoint protection by using Microsoft Defender for Endpoint
Answer Correct answer: B — Enabling Intune co-management alone does not auto-onboard devices to Defender for Endpoint; an Endpoint Detection and Response (EDR) policy is required.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You enable co-management. Does this meet the goal?

  1. Yes
  2. No Correct Answer

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The item tests whether you can separate the purpose of Intune co-management from the mechanism that actually onboards devices to Defender for Endpoint; the trap is assuming any Intune–Configuration Manager integration automatically covers Defender for Endpoint onboarding.

This MS-102 case-study item asks whether simply enabling Intune co-management causes enrolled devices to onboard automatically to Microsoft Defender for Endpoint. It establishes that the answer is No — co-management governs joint Configuration Manager and Intune device management, not Defender for Endpoint onboarding, which requires an Endpoint Detection and Response (EDR) policy in Intune.

The most common wrong answer is 'Yes', because learners associate co-management with tighter Intune/Configuration Manager integration and assume it carries Defender for Endpoint onboarding along with it — but co-management only splits device workloads between the two management authorities and never enrolls a device into Defender for Endpoint.

Community Discussion (3 comments)

Krayzr 👍 1 Selected: B
You create an endpoint detection and response (EDR) policy
KoenJas 👍 3
No, enabling co-management alone will not automatically onboard devices to Defender for Endpoint. Co-management is more about managing devices with both ConfigMgr (SCCM) and Intune, but it doesn't ensure automatic onboarding to Defender for Endpoint. The correct solution, as mentioned earlier, would be to create an Endpoint Detection and Response (EDR) policy.
Preeb 👍 3
Answer is: No Enabling co-management alone does not automatically onboard devices to Microsoft Defender for Endpoint when they are enrolled in Intune. Co-management allows you to manage devices with both Configuration Manager and Intune, but for automatic onboarding to Defender for Endpoint, you would need to configure the appropriate settings in Intune to ensure that the devices are onboarded to Defender for Endpoint upon enrollment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Co-management is an Intune plus Configuration Manager feature that lets a Windows device be managed simultaneously by both authorities and lets you shift specific workloads (compliance policies, resource access, Windows Update policies) from Configuration Manager to Intune. Nothing in the co-management configuration flow sends the device's onboarding package or writes the Defender for Endpoint sensor configuration, so devices that are merely co-managed remain un-onboarded to Defender for Endpoint. Automatic onboarding requires a distinct step in Intune — deploying an Endpoint Detection and Response policy (or configuring the Defender for Endpoint connector with auto-onboarding) so the device receives the onboarding blob when it enrolls. That is exactly why the community consensus here is uniformly negative: as KoenJas states, "enabling co-management alone will not automatically onboard devices to Defender for Endpoint." Therefore the proposed solution does not meet the goal, and answer B is correct.

Why the Other Options Are Wrong

Option A ('Yes') would only hold if enabling co-management itself pushed the Defender for Endpoint onboarding configuration to the device, which it does not — co-management changes who manages the device workload, not whether the Defender for Endpoint sensor is activated. The scenario's goal is specifically automatic onboarding at Intune enrollment, and co-management is neither a prerequisite nor a delivery mechanism for that onboarding payload. Note also that the question is a solution-evaluation item, so a partially related feature such as co-management cannot be accepted just because it touches the same device-management stack.

Community Comment Notes

Every recorded vote in this item landed on B, and the comment thread explains the missing piece consistently. Preeb puts it plainly: co-management "allows you to manage devices with both Configuration Manager and Intune," while automatic onboarding needs the appropriate Intune configuration instead. Krayzr supplies the concrete remedy — "You create an endpoint detection and response (EDR) policy" — and KoenJas identifies the same mechanism, saying the correct solution "would be to create an Endpoint Detection and Response (EDR) policy." This three-way agreement on the EDR policy as the real onboarding path is strong confirmation that the source key's 'No' is right.

Exam Strategy Tip

Because this is a solution-evaluation item, first restate the requirement in one clause ('devices auto-onboard to Defender for Endpoint at Intune enrollment') and then ask whether the named feature delivers that payload; if it only changes management ownership, answer No.

Official Reference

Exam Strategy

For solution-evaluation questions in this section, isolate the verb in the requirement — here 'automatically onboard to Defender for Endpoint' — and check whether the proposed feature actually delivers that configuration to the device, rather than merely changing how the device is managed. Co-management reallocates workloads between Configuration Manager and Intune, so it fails the test; an EDR onboarding policy passes it.

Frequently Asked Questions

Does enabling Intune co-management automatically onboard devices to Defender for Endpoint?

No. Co-management only lets Configuration Manager and Intune manage the same device and workload split; it does not push the Defender for Endpoint onboarding configuration.

What actually onboards Intune-enrolled devices to Defender for Endpoint automatically?

An Endpoint Detection and Response (EDR) policy in Intune, together with the Defender for Endpoint connector, delivers the onboarding configuration when the device enrolls.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide