Limiting Microsoft Defender device discovery to specific onboarded devices by creating a device tag first

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: D — Device discovery is scoped to specific devices through device tags, so you create the tag first and then limit Standard discovery to tagged devices.

You have 500 on-premises devices. You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You onboard 100 devices to Microsoft Defender 365. You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery. What should you do first?

  1. Create a device group.
  2. Create an exclusion.
  3. Set Discovery mode to Basic.
  4. Create a tag. Correct Answer

Community Votes

D
52%
C
48%

52% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Standard discovery is the default active mode that finds unmanaged devices, and it can be restricted to a subset of onboarded devices by specifying their device tags, so a tag is the mechanism that satisfies the 'only specific devices' constraint.

You must identify unmanaged on-premises devices but ensure only specific onboarded devices perform the discovery; the first step is to create a device tag, because Standard discovery can be scoped to run only on devices that carry a specified tag.

Setting Discovery mode to Basic — Basic is passive and does not address limiting discovery to specific devices, and Standard discovery (needed to find unmanaged devices) is already the default.

Community Discussion (15 comments)

DChilds 👍 7 Selected: C
C https://learn.microsoft.com/en-us/defender-endpoint/device-discovery?view=o365-worldwide
Optimizor_IT 👍 1 Selected: A
First, create a device group to include only the specific onboarded devices you want as discovery agents (e.g., 10 of the 100). Then, in Settings > Endpoints > Device discovery, set “Devices that will perform discovery” to “Only devices in specified device groups” and select your group. A device group (A) or tag (D) can do this, but A is the stronger starting point because: Groups are purpose-built for policy assignment in Defender. Groups support dynamic membership (e.g., based on attributes), unlike tags (manual). Post-group creation, you can configure discovery settings to use only that group.
Tamataya 👍 1 Selected: C
It is C according to ChatGPT
HAjouz 👍 1 Selected: C
C. Set Discovery mode to Basic.
Tuitor01 👍 2 Selected: D
Can I control which devices perform Standard discovery? You can customize the list of devices that are used to perform Standard discovery. You can either enable Standard discovery on all the onboarded devices that also support this capability (currently Windows 10 or later and Windows Server 2019 or later devices only) or select a subset or subsets of your devices by specifying their device tags. In this case, all other devices are configured to run Basic discovery only. The configuration is available in the device discovery settings page.
sapphire 👍 1 Selected: D
Select tags https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery-faq
VeiN 👍 2 Selected: D
You need to create a tag. By default Standard discovery is already turned on. Only when its turned on you can specify what onboarded devices will do Standard discovery. - ALL devices - only the ones which have specific tag So if you create first a tag and select the tag in this setting only those specified devices will do the discovery.
talosDevbot 👍 1 Selected: D
Important point in the question: "The solution must ensure that only specific onboarded devices perform the discovery" Standard discovery is the default and recommended mode. It'll provide results than Basic discovery so you don't need to set it to Basic. You can configure the Standard discovery scan to be performed by all onboarded devices or by a subset of devices. This is configured by specifying their device tag.
g_man_rap 👍 2
The requirement is to ensure that only specific onboarded devices perform the discovery. Simply setting the discovery mode to Basic does not address the need to limit discovery to specific devices. Instead, it changes the scope and intensity of the discovery but applies this setting globally, not selectively to specific devices.
g_man_rap 👍 1 Selected: A
The first step should be to create a device group. By doing so, you can group the specific onboarded devices that you want to perform the unmanaged device discovery. Once the group is created, you can configure discovery settings or apply policies that only affect that group, ensuring that only those specific devices handle the discovery task.
ddmitric 👍 1 Selected: D
On first look I thought C, but after reading question again and documentation, I would say D is right. "To set up device discovery, take the following configuration steps in Microsoft Defender portal: Navigate to Settings > Device discovery If you want to configure Basic as the discovery mode to use on your onboarded devices, select Basic and then select Save If you've selected to use Standard discovery, select which devices to use for active probing: all devices or on a subset by specifying their device tags, and then select Save"
threshclo 👍 1 Selected: D
standard scan is needed to specify which devices can perform discovery, so the answer to this question is D.
laddu001 👍 2
Set Discovery mode to Basic. T
wheeldj 👍 4 Selected: D
Answer D - Create a device tag. https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq#can-i-control-which-devices-perform-standard-discovery A- Device groups are not used to specify which device perform discovery scans B- Exclusions are used to exclude specific devices from being scanned, no control which devices perform the scane C- setting discovery mode to basic just controls the type of scan that's performed it doesn't limit scans to only be run from a specific list of devices. D- as per the above article Devices tags can be used to ensure Standard Discovery scans are only performed by specific devices with the assigned tag. All other managed devices are limited to basic scans only. this doesn't quite meet the requirement in the question which infers ALL scans must be limited to specific devices but it is all that MS support and therefore answer D is the closest to meeting this requirement.
ServerBrain 👍 2 Selected: C
Set Discovery Mode to Basic: Configure the Discovery mode for your onboarded devices. Choose Basic discovery mode to passively collect events in your network and extract device information from them. Basic discovery uses the SenseNDR.exe binary for passive network data collection, and no network traffic is initiated. Endpoints extract data from all network traffic seen by an onboarded device. Note that with basic discovery, you gain limited visibility of unmanaged endpoints in your network

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Defender for Endpoint device discovery, Standard discovery is the default active mode used to find unmanaged devices. You can configure which onboarded devices perform Standard discovery by selecting 'only devices with specific tags' in Settings > Device discovery. Therefore the first step to restrict discovery to specific devices is to create a tag and apply it to those devices.

Why the Other Options Are Wrong

Setting Discovery mode to Basic (C) switches to passive collection and does not let you pick specific devices; it also weakens the unmanaged-device discovery the scenario needs. Exclusions (B) remove devices from being scanned, not from performing discovery. Device groups (A) are not the control used for selecting discovery agents; the documented control is device tags.

Community Comment Notes

The community is split (D 48 vs C 44). wheeldj, Tuitor01, and VeiN cite https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq, which states you select a subset of devices by specifying their device tags. ddmitric and talosDevbot note Standard discovery is default and only needs tag-scoping, so D is the first step.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide