Uploaded January 2026 | Updated September 2026, 15 minutes ago
Submit your questions before 8:00 AM January 26: https://aka.ms/AMA/SecureEndpoints.
Have questions about using Microsoft Intune to enforce device compliance? Curious how to configure devices to help prevent security breaches and limit the impact of threats? Ask Microsoft Anything (AMA) about integrating Microsoft Defender for Endpoint with Microsoft Intune at Tech Community Live!
Product teams will be answering your questions live and in chat. Get tips using policy to onboard devices, define risk level, block non-compliant devices from accessing corporate resources, and more.
This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition. π For the full agenda, see: https://aka.ms/TCL/Intune
0:00 β Welcome & introductions
1:36 β Question β Youβre spending a lot of time on copilot/AI integrations into the product. Itβs been helpful to see how this shows up in the product. Can you share more about how youβre infusing the Settings process with AI?
6:26 β Question β I have started applying security policies for Defender for Endpoint using MDE to manage them, adding the MDE tag to my Windows 11 machines. If I am migrating to Intune management, is it necessary to offboard the devices first, before applying the auto-enroll GPO and onboarding device configuration to the machines?
12:27 β Question β If we are pre-provisioning devices using Autopilot, how long will it take for them to report in as compliant in Defender?
16:46 β Question β Apologies if this was mentioned earlier, but to which licensing model is this applicable to? E5?
17:11 β Question β Can you provide greater clarity regarding the distinctions between Medium, High, and other risk levels? Concerned that overly stringent Defender requirements may adversely affect the overall Intune MDM user experience.
22:54 β Question β Do you have anything currently available or in development that will act similar to GPresult/RSOP (result set up policy) to see what settings are applied via Intune on a device and what policy applies the setting?
32:03 β Question β In a mixed environment (Entra ID joined + hybrid joined + a few BYOD), whatβs your recommended baseline policy stack in Intune + Defender so we avoid overlapping controls and false positives? And how do you decide what belongs in Intune vs Defender?
40:00 β Question β Can we apply a compliance policy for risk level if the computer has Defender but is not in Intune it is manage from different MDM?
44:37 β Question β Can we only use MS Defender for Intune managed devices? What are the prerequisites?
46:05 β Question β So, with Intune, Defender for Cloud/M365, where is the overlap with Purview? As long as your environment is stood up using CAF/WAF with proper management groups that are top down? -- Note for audience -- CAF = Cloud Adoption Framework and WAF = Well-Architected Framework
50:57 β Question β Do you recommend the security baselines in Intune?
Submit your questions before 8:00 AM January 26: https://aka.ms/AMA/SecureEndpoints.
Have questions about using Microsoft Intune to enforce device compliance? Curious how to configure devices to help prevent security breaches and limit the impact of threats? Ask Microsoft Anything (AMA) about integrating Microsoft Defender for Endpoint with Microsoft Intune at Tech Community Live!
Product teams will be answering your questions live and in chat. Get tips using policy to onboard devices, define risk level, block non-compliant devices from accessing corporate resources, and more.
This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition. π For the full agenda, see: https://aka.ms/TCL/Intune
0:00 β Welcome & introductions
1:36 β Question β Youβre spending a lot of time on copilot/AI integrations into the product. Itβs been helpful to see how this shows up in the product. Can you share more about how youβre infusing the Settings process with AI?
6:26 β Question β I have started applying security policies for Defender for Endpoint using MDE to manage them, adding the MDE tag to my Windows 11 machines. If I am migrating to Intune management, is it necessary to offboard the devices first, before applying the auto-enroll GPO and onboarding device configuration to the machines?
12:27 β Question β If we are pre-provisioning devices using Autopilot, how long will it take for them to report in as compliant in Defender?
16:46 β Question β Apologies if this was mentioned earlier, but to which licensing model is this applicable to? E5?
17:11 β Question β Can you provide greater clarity regarding the distinctions between Medium, High, and other risk levels? Concerned that overly stringent Defender requirements may adversely affect the overall Intune MDM user experience.
22:54 β Question β Do you have anything currently available or in development that will act similar to GPresult/RSOP (result set up policy) to see what settings are applied via Intune on a device and what policy applies the setting?
32:03 β Question β In a mixed environment (Entra ID joined + hybrid joined + a few BYOD), whatβs your recommended baseline policy stack in Intune + Defender so we avoid overlapping controls and false positives? And how do you decide what belongs in Intune vs Defender?
40:00 β Question β Can we apply a compliance policy for risk level if the computer has Defender but is not in Intune it is manage from different MDM?
44:37 β Question β Can we only use MS Defender for Intune managed devices? What are the prerequisites?
46:05 β Question β So, with Intune, Defender for Cloud/M365, where is the overlap with Purview? As long as your environment is stood up using CAF/WAF with proper management groups that are top down? -- Note for audience -- CAF = Cloud Adoption Framework and WAF = Well-Architected Framework
50:57 β Question β Do you recommend the security baselines in Intune?










