nerdexam
Microsoft

MD-102 · Question #296

You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for…

The correct answer is C. an endpoint detection and response (EDR) policy. An Endpoint Detection and Response (EDR) policy in the Microsoft Intune admin center is specifically designed to onboard Windows devices to Microsoft Defender for Endpoint. It deploys the Defender for Endpoint onboarding configuration package to devices, enabling the EDR…

Submitted by the_admin· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for Endpoint. What should you create in the Microsoft Intune admin center?

Options

  • Aan attack surface reduction (ASR) policy
  • Ba security baseline
  • Can endpoint detection and response (EDR) policy
  • Dan account protection policy
  • Ean antivirus policy

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    77% (20)
  • D
    12% (3)

Explanation

An Endpoint Detection and Response (EDR) policy in the Microsoft Intune admin center is specifically designed to onboard Windows devices to Microsoft Defender for Endpoint. It deploys the Defender for Endpoint onboarding configuration package to devices, enabling the EDR sensor. An ASR policy (A) reduces attack surfaces but does not perform onboarding. A security baseline (B) applies hardening settings but is not the onboarding mechanism. An account protection policy (D) protects credentials. An antivirus policy (E) configures Defender Antivirus settings. Only the EDR policy handles the Defender for Endpoint onboarding workflow.

Topics

#Defender for Endpoint#EDR policy#Intune enrollment#Windows 11

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice