Which Portal Assigns the Microsoft Defender for Endpoint Baseline?

Implement and manage endpoint protection by using Microsoft Defender for Endpoint
Answer Correct answer: A — Assign the Microsoft Defender for Endpoint baseline from the Microsoft Intune admin center under Endpoint security > Security baselines.

You have a Microsoft 365 E5 subscription. You need to assign a Microsoft Defender for Endpoint baseline. Which portal should you use?

  1. the Microsoft Intune admin center Correct Answer
  2. the Microsoft Purview compliance portal
  3. the Microsoft Defender portal
  4. the Microsoft 365 admin center

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests where baseline profiles are authored and assigned for Defender for Endpoint; the trap is assuming the Microsoft Defender portal, which surfaces alerts and incidents, must also be where the baseline is deployed.

Assigning the Microsoft Defender for Endpoint security baseline is performed in the Microsoft Intune admin center under Endpoint security > Security baselines. This page confirms that the Intune admin center — not the Defender portal or the Microsoft 365 admin center — is the correct portal for baseline assignment in an E5 subscription.

Choosing the Microsoft Defender portal because its name matches 'Defender for Endpoint' — but the Defender portal is the detection and investigation surface, while baseline profiles are created and assigned as Intune endpoint security profiles.

Community Discussion (7 comments)

Xive 👍 5 Selected: A
Baseline are always set in Intune. So I will go with the given answer.
justITtopics 👍 3 Selected: A
Intune admin center->Endpoint Security->Security baselines. Here you can choose from: Security Baseline for Windows 10 and later, Microsoft Defender for Endpoint Security Baseline and more
Hiyas 👍 2 Selected: A
seems Intune is correct
hurtgeym 👍 3
o configure a Microsoft Defender for Endpoint baseline, you should use the Microsoft Intune admin center. Here are the steps: Sign in to the Microsoft Intune admin center. Navigate to Endpoint security > Security baselines. Select the Microsoft Defender for Endpoint baseline. Click on Create profile.
7d01a47 👍 1 Selected: C
Both Microsoft Intune Admin portal and Microsoft Defender portals work together to provide endpoint security and management, the Microsoft Defender portal is the appropriate and dedicated interface for assigning Microsoft Defender for Endpoint baselines. Using Intune may allow for device management but does not provide the necessary tools for configuring and assigning these specific security settings effectively. Thus, for assigning baselines, the most effective and appropriate choice is the Microsoft Defender portal.
7d01a47 👍 1
C. the Microsoft Defender portal
Preeb 👍 2
C. the Microsoft Defender portal The Microsoft Defender portal is specifically designed for managing security configurations, including baselines for Defender for Endpoint.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Microsoft Defender for Endpoint baseline is delivered as a security baseline profile inside the Microsoft Intune admin center, reached through Endpoint security > Security baselines. Baseline templates — including the Defender for Endpoint baseline — are created, targeted to device groups, and assigned there, which is exactly what the question asks for. The subscription type (Microsoft 365 E5) grants the licensing needed for Defender for Endpoint and Intune, so no portal restriction pushes the task elsewhere. Community consensus backs this: as Xive put it, "Baseline are always set in Intune," and justITtopics described the exact path "Intune admin center->Endpoint Security->Security baselines" where you pick the "Microsoft Defender for Endpoint Security Baseline." hurtgeym listed the same steps. Therefore option A is the portal to use.

Why the Other Options Are Wrong

The Microsoft Purview compliance portal (B) hosts compliance, DLP, and information protection workloads, not Defender for Endpoint baseline profiles. The Microsoft Defender portal (C) is the XDR surface for incidents, advanced hunting, and alert triage — a tempting choice because of its name, as Preeb argued in favor of "the Microsoft Defender portal," and 7d01a47 claimed it is "the appropriate and dedicated interface for assigning" baselines. That conflates monitoring with configuration; baseline assignment is an Intune endpoint security action, and the two portals work together rather than the Defender portal replacing Intune for profiles. The Microsoft 365 admin center (D) handles tenant-level settings, licenses, and user administration, and contains no per-device security baseline profiles.

Community Comment Notes

Virtually all voters here landed on Intune: Xive and Hiyas both leaned to Intune, with Hiyas noting "seems Intune is correct." The most useful comments were procedural — hurtgeym's walkthrough of "Endpoint security > Security baselines" and the "Create profile" step, and justITtopics' list of available templates including the Defender for Endpoint baseline. The dissenting views (Preeb, 7d01a47) rested on the mistaken premise that the Defender portal is where Defender for Endpoint settings are assigned; 7d01a47's own phrasing that the portals "work together" actually supports Intune as the configuration plane.

Official Reference

Exam Strategy

Memorize the division of labor: Intune configures and assigns endpoint security baselines, while the Microsoft Defender portal consumes the resulting telemetry for detection and response. When an MS-102 question says 'assign' or 'create a profile,' the answer is almost always Intune.

Frequently Asked Questions

Why is the Microsoft Defender portal wrong for assigning the Defender for Endpoint baseline?

The Defender portal is for incidents, alerts and advanced hunting; baseline profiles are created and targeted to device groups as Intune endpoint security profiles.

What licensing is required to use the Defender for Endpoint baseline?

The Microsoft 365 E5 subscription in the scenario already includes Intune and Defender for Endpoint, so both the baseline templates and the Intune admin center are available.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide