Enable Microsoft Defender for Endpoint integrations
To enable the connection in Defender for Endpoint follow the following steps:
- Sign in to the security.microsoft.com portal
- Go to Endpoints -> Advanced Features
- Turn on the feature Microsoft Intune connection

For checking the state and configuring more settings go to the Intune portal and select Microsoft Defender for Endpoint.
Connection status and last synchronized shows the status between MDE and Intune.

Now lets get back to the steps available for the Defender for Endpoint Device Onboarding process. There are multiple methods available.
Step 1- Login in to Defender Microsoft 365 portal using below URL.
https://security.microsoft.com
Step 2- On the Settings > Click Endpoints
![clip_image002[4] clip_image002[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0024_thumb.png?w=1013&h=772)
Step 3- Click Onboarding
![clip_image004[4] clip_image004[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0044_thumb.png?w=1028&h=703)
Step 4- On the “Select operating System to Start Onboarding Process” > Select Windows 10 and 11

Step 5- On the “Deployment Method”, Select Mobile Device Management / Intune
![clip_image008[4] clip_image008[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0084_thumb.png?w=1028&h=556)
Step 6- Click “Download Onboarding Package”
![clip_image010[4] clip_image010[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0104_thumb.png?w=1028&h=453)
Step 7- Once downloaded the package you can push it through the MEM console. Lets have a look how we do that using Microsoft Endpoint Manager.
Login in to Endpoint Manager Console using the below link
https://endpoint.microsoft.com
Step 8- Select Devices > Policy > Select Device Configuration Policy
Note: To onboard the Windows devices to Defender for endpoint, we are going to create OMA-URI settings in Endpoint Manager using the previously downloaded Onboarding Package.

Step 9- Select “Configuration Profiles” > Select “Create Profile”
![clip_image014[4] clip_image014[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0144_thumb.png?w=1028&h=609)
Step 10- On the Create Profile menu, under Platform Select Windows 10 and Later and, On the Profile Type Select Templates > Select Custom > Select Create

Step 11- On the Basics menu, put a meaningful name and a description for the Policy and Click Next
![clip_image018[4] clip_image018[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0184_thumb.png?w=826&h=772)
Step 12- On the Configuration Settings Click Add to create the OMA-URI settings.
On the OMA URI settings do the following.
- · Name- Device Onboard
- · Description- Defender for endpoint enrollment
- · OMA-URI- ./Device/Vendor/MSFT/WindowsAdvancedThreatProtection/Onboarding
- · Data Type-String
- · Value- Extract the downloaded onboard package and open it with .txt format and copy the content inside the file
Once added the correct details Click Save > Click Next
![clip_image021[4] clip_image021[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0214_thumb.png?w=556&h=772)
Step 13- On the “Assignments” page add the required Device group and Click Next
![clip_image023[4] clip_image023[4]](https://methmal132.files.wordpress.com/2022/03/clip_image0234_thumb.png?w=705&h=772)
Step 14- Click Next on the Applicability Rules unless of you don’t have any specific way which you need this rule to be applied. For instance, if the OS edition or OS version is not now equal to what you have in your environment or etc.

Step 15- On the review+ Create menu, make sure what you did in the previous steps are correct and Click “Create” Button to finish the policy creation.
Endpoint Security Profile Settings
Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations is needed when using Microsoft Defender for Endpoint to enforce Endpoint Security Configurations. The setting is only for managing the configuration after the initial Defender for Endpoint onboarding.
Compliance
For compliance integrations, multiple settings can be enabled. When using Intune it is possible to use compliance policies for requiring compliant devices. Signals from Defender for Endpoint can be used for calculating the compliance or noncompliance state. (Require devices to be at or under the machine risk score)

The following controls are available for Defender AV:

In the Endpoint Security the following settings are part of the compliance integrations with Defender for Endpoint and can be enabled:
- Connect Android devices version 6.0.0 and above to Microsoft Defender for Endpoint
- Connect iOS/iPadOS devices version 13.0 and above to Microsoft Defender for Endpoint
- Connect Windows devices version 10.0.15063 and above to Microsoft Defender for Endpoint
- Enable App Sync (sending application inventory) for iOS/iPadOS devices
- Block unsupported OS versions
For Windows make sure the toggle Connect Windows devices version 10.0.15063 and above to Microsoft Defender for Endpoint is enabled.

App protection policy evaluation
App Protection can be enabled for mobile platforms (iOS / Android). With the use of App protection policies, it is possible to restrict access when prerequisites are not matched (Max allowed device threat level). For example; when the device threat level contains Low – access to corporate data can be restricted.
The feature works only for iOS/ Android.

Onboarding through Endpoint detection and response profile
Create onboarding profile
After configuring Microsoft Defender for Endpoint in Intune, the next step is to onboard the devices in Defender for Endpoint.
Multiple ways are currently available in Intune for completing the onboarding of Defender for Endpoint. Advised is to use the Endpoint Security profiles in Intune.
For creating the Endpoint detection and response/ MDE onboarding profile:
- Go to the Intune portal and go to Endpoint Security
- Select Endpoint Detection and response and click on Create Policy

- Select Platform: Windows 10, Windows 11, and Windows Server and Profile: Endpoint detection and response

On the Basics section, specify the profile name and optional description. The configuration settings contain all features which are needed for the initial onboarding. There are three settings that are relevant for the onboarding:
- Microsoft Defender for Endpoint client configuration package type
- Sample sharing
- Telemetry Reporting Frequency (deprecated)
Microsoft Defender for Endpoint client configuration package type is needed for assigning the configuration package. When Intune/ MDE are completely synced it is part of the connection. The following options are available:
- Auto from connector
- Onboard
- Offboard
When connected using the Auto from connector option; Intune automatically gets the onboarding package (blob) from the Defender for Endpoint deployment. There is no need for manually onboarding the package.

When there is no connection possible between Intune/ MDE or Intune is not configured in the same tenant where Defender for Endpoint is configured – the option onboard can be used. In the option onboard the custom blob value can be configured.
Sample sharing is part of Defender for Endpoint and is needed for sample sharing with Microsoft. Sample sharing can be Enabled/Disabled. To take full benefits from the cloud layer it is advised to use always Sample Sharing.

Telemetry Reporting Frequency is another setting part of the Defender for Endpoint profile which can be configured in two levels (Normal/ Expedite)
By default, the telemetry reporting frequency is based on the normal frequency. I always recommend the Expedite telemetry frequency for Defender for Endpoint.
Update July 2023: The Telemetry Reporting Frequency setting is currently deprecated and no longer needed/ removed from the profile list. Configure this setting with Not Configured

After some time, Defender for Endpoint is deployed and the SENSE service must be running on the device. Using the build-in assignment reporting in Intune the deployment state can be validated.

Registry
In the registry the following path is interesting; Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
The path contains the onboarding info and additional settings. OnboardingInfo contains the organization ID, geoLocation, and blob value.
Contents from the below links.
https://jeffreyappel.nl/microsoft-defender-for-endpoint-series-onboard-using-microsoft-intune-part3a