Onboard iOS Devices to Microsoft Defender for Endpoint via Intune
You have a Microsoft 365 E5 subscription that includes Microsoft Intune. You manage all iOS devices by using Intune. You plan to protect corporate-owned iOS devices by using Microsoft Defender for Endpoint. You configure a connection between Intune and Defender for Endpoint. You need to onboard the devices to Defender for Endpoint. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the difference between agent-based onboarding (Windows/macOS) and app-based deployment (iOS) in the context of Intune integration.
This page clarifies the correct method to onboard corporate-owned iOS devices to Microsoft Defender for Endpoint using Intune. It explains that deploying the specific app is required, contrary to Windows/macOS onboarding packages.
Most candidates choose 'Download an onboarding package' because this is the standard procedure for Windows and macOS devices, leading them to incorrectly apply the same logic to iOS.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
For iOS devices managed by Intune, Microsoft Defender for Endpoint is deployed as a native application rather than through a background agent script. The correct action is to add the Microsoft Defender for Endpoint app to Intune (Option D). By adding the iOS store app to Intune, administrators can deploy it to enrolled user groups, ensuring the security solution is installed and active on the corporate-owned devices.Why the Other Options Are Wrong
Option A is incorrect because onboarding packages are used for Windows and macOS devices to configure the sensor and connect to the service; they are not applicable to iOS. Option B, creating an app protection policy, secures data within apps but does not install or onboard the endpoint detection tool itself. Option C refers to Microsoft Defender for Cloud, which is a cloud security posture management tool unrelated to device-level endpoint protection.Community Comment Notes
Community consensus initially favored Option D, with users noting that the term "Add an app" specifically refers to adding the iOS store app in the Intune admin center. Some users were confused by the phrasing, preferring the term "onboarding package," but verified that for iOS, the mechanism is app deployment. One commenter explicitly stated that downloading an onboarding package is used for Windows/macOS only, reinforcing why D is the distinct correct choice for iOS.Official Reference
Exam Strategy
Always distinguish between OS-specific deployment methods. For Windows/macOS, look for 'onboarding package' or 'agent'. For iOS/iPadOS, look for 'app deployment' or 'store app' when integrating third-party or Microsoft security apps via Intune.
Frequently Asked Questions
Why isn't 'Download an onboarding package' correct for iOS?
Onboarding packages are scripts/configs for Windows and macOS sensors. iOS uses the Microsoft Defender for Endpoint app from the App Store.
What does 'Add an app' mean in Option D?
It means adding the Microsoft Defender for Endpoint iOS store app in the Intune Admin Center and assigning it to user groups.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →