Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Typically, you create and manage endpoint security policies in the Microsoft Intune admin center. Intune can apply these policies to enrolled devices. With Defender for Endpoint security settings management, Intune can also apply supported policies to devices that are onboarded to Defender for Endpoint but aren't enrolled in Intune.
After you configure the connection between Intune and Defender for Endpoint and enable security settings management as described in Manage Defender for Endpoint security settings, you can also create and manage supported endpoint security policies in the Microsoft Defender portal.
Managing endpoint security policies in the Defender portal has the following benefits:
- Work from a single console.
- Apply one policy to both Intune-enrolled devices and devices managed through Defender for Endpoint security settings management.
- Manage security settings using Defender for Endpoint permissions rather than a full Intune administrator role.
Use the procedures in this article to create and manage policies on the Endpoint security policies page in the Microsoft Defender portal at https://security.microsoft.com/policy-inventory.
Prerequisites
You need the appropriate permissions to complete the procedures in this article.
- Your permissions must apply to all devices. If your role is scoped to specific device groups, you can't open the Endpoint security policies page.
- Regardless of which of the following options grants you access, the list of policies shown in the Microsoft Defender portal is scoped by your Intune role-based access control (RBAC) assignments.
You have the following options to assign the required permissions:
Microsoft Defender Unified role-based access control (RBAC):
- Create and manage policies: Authorization and settings/Security settings/Core Security settings (manage)
- Read-only access to policies: Authorization and settings/Security settings/Core Security settings (read)
Microsoft Intune role-based access control (RBAC): Microsoft recommends the Intune built-in Endpoint Security Manager role to align the level of permissions between Intune and the Microsoft Defender portal.
Microsoft Entra permissions: Membership in the Global Administrator*, Security Administrator, or Intune Administrator roles gives users the required permissions and permissions for other features in Microsoft 365.
Important
* Microsoft strongly advocates for the principle of least privilege. Assigning accounts only the minimum permissions necessary to perform their tasks helps reduce security risks and strengthens your organization's overall protection. Global Administrator is a highly privileged role that you should limit to emergency scenarios or when you can't use a different role.
Supported endpoint security policies
The following table lists the endpoint security policy types you can manage and the platforms that each type supports:
Note
You can't use endpoint security policy management on devices that are running a sensor delivered by the Microsoft Monitoring Agent (MMA). For information about upgrading these devices, see Use the Defender deployment tool to deploy Defender endpoint security.
Also, only the Microsoft Defender Antivirus policy is supported on Windows 7 SP1 and Windows Server 2008 R2 SP1.
| Policy | Windows | macOS | Linux |
|---|---|---|---|
| Attack surface reduction (ASR) rules | Yes | ||
| Defender update controls | Yes | ||
| Device control | YesÂđ | ||
| Endpoint detection and response (EDR) | Yes | Yes | Yes |
| Microsoft Defender Antivirus | Yes | Yes | Yes |
| Microsoft Defender Antivirus exclusions | Yes | Yes | Yes |
| Microsoft Defender Firewall | Yes | ||
| Microsoft Defender Firewall rules | Yes | ||
| Microsoft Defender global exclusions (antivirus and EDR) | Yes | ||
| Windows Security experience | Yes |
Âđ Device control policies are available in the Defender portal, but they apply only to devices enrolled in Microsoft Intune. They don't apply to devices managed only through Defender for Endpoint security settings management.
Create an endpoint security policy
To create an endpoint security policy, follow these steps:
On the Endpoint security policies page in the Microsoft Defender portal at https://security.microsoft.com/policy-inventory, select
Create new policy.The tab you start on doesn't matter because you can create a policy for any operating system from any tab. After creation, the policy appears on the tab for its operating system.
In the Create a new policy flyout that opens, choose from the following options:
Select platform: Choose one of the following values:
- Windows
- macOS
- Linux
After you select the platform, Select template appears. For the templates available on each platform, see Supported endpoint security policies.
After you select a template, select Create policy.
The new policy wizard opens. On the Basics page, configure the following settings:
- Name: Enter a unique, descriptive name for the policy.
- Description: Enter an optional description for the policy.
When you're finished on the Basics page, select Next.
On the Configuration settings page, the available settings depend on the policy platform and template.
You can use the
Search box to find settings.When you're finished on the Configuration settings page, select Next.
On the Assignments page, use the
Search box to find and select a group to assign the policy to. Intune policy assignments use Microsoft Entra security groups. For information about supported group types and membership, see Use groups to organize users and devices for Microsoft Intune.Important
For devices managed through Defender for Endpoint security settings management (devices onboarded to Defender for Endpoint but not enrolled in Intune), assignments support device objects only. Assign the policy to Microsoft Entra device groups, not user groups, because user targeting isn't supported for these devices. For Intune-enrolled devices, you can assign the policy to user groups or device groups.
After you select a group, the following information is shown on the page:
- Group: The group name.
- Group members: The number of affected devices and users.
- Target type: You can select Include (default) or Exclude to include or exclude the members of the group from the policy.
Repeat this step to assign more groups.
When you're finished on the Assignments page, select Next.
On the Review + create page, review your settings. Use the Back button to modify the settings.
When you're finished on the Review + create page, select Save.
After the policy creation finishes, you're taken to the detailed settings of the policy as if you selected it on the Endpoint security policies page.
Note
The Defender portal policy wizard doesn't support scope tags or assignment filters. To use these features, create or edit the policy in the Microsoft Intune admin center.
Edit an endpoint security policy
To modify an endpoint security policy, follow these steps:
On the Endpoint security policies page in the Defender portal, select an available tab:
On the appropriate tab, select the policy by using any of the following methods:
- Select the check box next to the policy, and then select the
Edit action that appears. - Select the policy name (link). On the policy page that opens, select
Edit. - Select anywhere in the row other than the check box or the policy name. In the policy details flyout that opens, select
Edit.
- Select the check box next to the policy, and then select the
In the policy wizard, review or change the Basics, Configuration settings, and Assignments pages. On the Review + create page, review the policy, and then select Save.
The policy page opens after the changes are saved.
Verify endpoint security policies
To confirm that you successfully created a policy, verify the policy is listed on the appropriate tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory.
Select the policy name (link) to open the policy page. The policy page summarizes the status of the policy. You can view the policy's status, which devices it applies to, and the assigned groups.
Devices managed through Defender for Endpoint security settings management check in with Intune every 90 minutes for policy updates. To request an on-demand policy sync:
- On the appropriate tab of the Device inventory page in the Defender portal at https://security.microsoft.com/machines, select the Name value of the device.
- On the device entity page that opens, select
More actions, and then select
Policy sync.
The policy should be applied in about 10 minutes.
During an investigation, use the Security policies tab in the Configuration management section of the device entity page to view the policies applied to the device. For more information, see Investigating devices.