Does a Device Configuration Profile Onboard Devices to Defender for Endpoint?
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You configure a device configuration profile. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the difference between the Intune device configuration profile method and the EDR policy method for Defender for Endpoint onboarding; the trap is assuming only an EDR policy can onboard devices.
This question asks whether configuring a device configuration profile in Intune is enough to automatically onboard enrolled devices to Microsoft Defender for Endpoint. The answer is Yes — the onboarding configuration profile is applied as part of Intune enrollment, so devices onboard without manual steps.
Answering No on the belief that only an EDR policy (or the Defender for Endpoint connector) can onboard devices automatically — a custom OMA-URI device configuration profile is still a documented, supported onboarding method.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft's MDM onboarding guidance for Defender for Endpoint states that you can onboard devices with either a custom configuration policy or an EDR policy, and the custom policy is delivered as a device configuration profile containing the Defender for Endpoint onboarding package via OMA-URI. Because that profile is targeted at the device group, it is applied during Intune enrollment, which is exactly the "automatically onboard when they are enrolled" goal in the scenario. Nothing in the question requires the newer EDR policy type or the Defender for Endpoint connector, so a device configuration profile satisfies the requirement. Answering Yes (A) is therefore correct.Why the Other Options Are Wrong
"No" (B) would only be defensible if the scenario demanded a specific mechanism such as an endpoint detection and response policy or a connector-based auto-onboarding flow. The question instead states a generic goal — devices must onboard to Defender for Endpoint automatically at Intune enrollment — and a device configuration profile with the onboarding configuration achieves that. A plain compliance policy or a security baseline would not onboard a device, but that is not the solution proposed here; the proposed solution is the configuration profile, which is valid. Treating the custom configuration profile as "not a real method" is the reasoning error behind option B.Community Comment Notes
Xive points out that "Device configuration policy is one of the first way to onboard with Intune" and that EDR policy came later, which matches the historical documentation order. kaspen similarly explains that a device configuration profile in Intune carries the settings needed to onboard devices to Defender for Endpoint as soon as enrollment completes. northgaterebel answered No and cited Microsoft's MDM guidance, quoting "you can use a custom configuration policy or an EDR policy" — but that sentence actually supports Yes, since a custom configuration policy is precisely the OMA-URI device configuration profile described in the scenario. Hamouda1 lands on the same Yes verdict, and the overwhelming vote for A reflects this reading.Official Reference
Exam Strategy
For MS-102 case-study items, judge whether the proposed method actually delivers the stated outcome at the stated trigger point (here, enrollment), not whether it is the newest method. If the profile applies the onboarding configuration to the target device group, the goal is met even when an EDR policy would also work.
Frequently Asked Questions
Is a device configuration profile still a valid way to onboard devices to Defender for Endpoint?
Yes. Microsoft's MDM onboarding guidance lists both a custom configuration policy and an EDR policy, so the older custom OMA-URI profile method remains supported.
Why do some learners answer No for this scenario?
They assume only the EDR policy or the Defender for Endpoint connector can onboard devices. The question only requires automatic onboarding at Intune enrollment, which the configuration profile provides.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →