Does Co-management Auto-Onboard Devices to Defender for Endpoint?
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You enable co-management. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The item tests whether you can separate the purpose of Intune co-management from the mechanism that actually onboards devices to Defender for Endpoint; the trap is assuming any Intune–Configuration Manager integration automatically covers Defender for Endpoint onboarding.
This MS-102 case-study item asks whether simply enabling Intune co-management causes enrolled devices to onboard automatically to Microsoft Defender for Endpoint. It establishes that the answer is No — co-management governs joint Configuration Manager and Intune device management, not Defender for Endpoint onboarding, which requires an Endpoint Detection and Response (EDR) policy in Intune.
The most common wrong answer is 'Yes', because learners associate co-management with tighter Intune/Configuration Manager integration and assume it carries Defender for Endpoint onboarding along with it — but co-management only splits device workloads between the two management authorities and never enrolls a device into Defender for Endpoint.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Co-management is an Intune plus Configuration Manager feature that lets a Windows device be managed simultaneously by both authorities and lets you shift specific workloads (compliance policies, resource access, Windows Update policies) from Configuration Manager to Intune. Nothing in the co-management configuration flow sends the device's onboarding package or writes the Defender for Endpoint sensor configuration, so devices that are merely co-managed remain un-onboarded to Defender for Endpoint. Automatic onboarding requires a distinct step in Intune — deploying an Endpoint Detection and Response policy (or configuring the Defender for Endpoint connector with auto-onboarding) so the device receives the onboarding blob when it enrolls. That is exactly why the community consensus here is uniformly negative: as KoenJas states, "enabling co-management alone will not automatically onboard devices to Defender for Endpoint." Therefore the proposed solution does not meet the goal, and answer B is correct.Why the Other Options Are Wrong
Option A ('Yes') would only hold if enabling co-management itself pushed the Defender for Endpoint onboarding configuration to the device, which it does not — co-management changes who manages the device workload, not whether the Defender for Endpoint sensor is activated. The scenario's goal is specifically automatic onboarding at Intune enrollment, and co-management is neither a prerequisite nor a delivery mechanism for that onboarding payload. Note also that the question is a solution-evaluation item, so a partially related feature such as co-management cannot be accepted just because it touches the same device-management stack.Community Comment Notes
Every recorded vote in this item landed on B, and the comment thread explains the missing piece consistently. Preeb puts it plainly: co-management "allows you to manage devices with both Configuration Manager and Intune," while automatic onboarding needs the appropriate Intune configuration instead. Krayzr supplies the concrete remedy — "You create an endpoint detection and response (EDR) policy" — and KoenJas identifies the same mechanism, saying the correct solution "would be to create an Endpoint Detection and Response (EDR) policy." This three-way agreement on the EDR policy as the real onboarding path is strong confirmation that the source key's 'No' is right.Exam Strategy Tip
Because this is a solution-evaluation item, first restate the requirement in one clause ('devices auto-onboard to Defender for Endpoint at Intune enrollment') and then ask whether the named feature delivers that payload; if it only changes management ownership, answer No.Official Reference
Exam Strategy
For solution-evaluation questions in this section, isolate the verb in the requirement — here 'automatically onboard to Defender for Endpoint' — and check whether the proposed feature actually delivers that configuration to the device, rather than merely changing how the device is managed. Co-management reallocates workloads between Configuration Manager and Intune, so it fails the test; an EDR onboarding policy passes it.
Frequently Asked Questions
Does enabling Intune co-management automatically onboard devices to Defender for Endpoint?
No. Co-management only lets Configuration Manager and Intune manage the same device and workload split; it does not push the Defender for Endpoint onboarding configuration.
What actually onboards Intune-enrolled devices to Defender for Endpoint automatically?
An Endpoint Detection and Response (EDR) policy in Intune, together with the Defender for Endpoint connector, delivers the onboarding configuration when the device enrolls.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →