Limiting Microsoft Defender device discovery to specific onboarded devices by creating a device tag first
You have 500 on-premises devices. You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You onboard 100 devices to Microsoft Defender 365. You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery. What should you do first?
Community Votes
52% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Standard discovery is the default active mode that finds unmanaged devices, and it can be restricted to a subset of onboarded devices by specifying their device tags, so a tag is the mechanism that satisfies the 'only specific devices' constraint.
You must identify unmanaged on-premises devices but ensure only specific onboarded devices perform the discovery; the first step is to create a device tag, because Standard discovery can be scoped to run only on devices that carry a specified tag.
Setting Discovery mode to Basic — Basic is passive and does not address limiting discovery to specific devices, and Standard discovery (needed to find unmanaged devices) is already the default.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Defender for Endpoint device discovery, Standard discovery is the default active mode used to find unmanaged devices. You can configure which onboarded devices perform Standard discovery by selecting 'only devices with specific tags' in Settings > Device discovery. Therefore the first step to restrict discovery to specific devices is to create a tag and apply it to those devices.Why the Other Options Are Wrong
Setting Discovery mode to Basic (C) switches to passive collection and does not let you pick specific devices; it also weakens the unmanaged-device discovery the scenario needs. Exclusions (B) remove devices from being scanned, not from performing discovery. Device groups (A) are not the control used for selecting discovery agents; the documented control is device tags.Community Comment Notes
The community is split (D 48 vs C 44). wheeldj, Tuitor01, and VeiN cite https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq, which states you select a subset of devices by specifying their device tags. ddmitric and talosDevbot note Standard discovery is default and only needs tag-scoping, so D is the first step.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →