AMA: Secure your endpoints with policy and Microsoft Defender @WindowsAtWork
AMA: Secure your endpoints with policy and Microsoft Defender  @WindowsAtWork
Uploaded January 2026 | Updated September 2026, 15 minutes ago
Submit your questions before 8:00 AM January 26: https://aka.ms/AMA/SecureEndpoints.

Have questions about using Microsoft Intune to enforce device compliance? Curious how to configure devices to help prevent security breaches and limit the impact of threats? Ask Microsoft Anything (AMA) about integrating Microsoft Defender for Endpoint with Microsoft Intune at Tech Community Live!

Product teams will be answering your questions live and in chat. Get tips using policy to onboard devices, define risk level, block non-compliant devices from accessing corporate resources, and more.

This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition. πŸ“ƒ For the full agenda, see: https://aka.ms/TCL/Intune

0:00 – Welcome & introductions

1:36 – Question – You’re spending a lot of time on copilot/AI integrations into the product. It’s been helpful to see how this shows up in the product. Can you share more about how you’re infusing the Settings process with AI?

6:26 – Question – I have started applying security policies for Defender for Endpoint using MDE to manage them, adding the MDE tag to my Windows 11 machines. If I am migrating to Intune management, is it necessary to offboard the devices first, before applying the auto-enroll GPO and onboarding device configuration to the machines?

12:27 – Question – If we are pre-provisioning devices using Autopilot, how long will it take for them to report in as compliant in Defender?

16:46 – Question – Apologies if this was mentioned earlier, but to which licensing model is this applicable to? E5?

17:11 – Question – Can you provide greater clarity regarding the distinctions between Medium, High, and other risk levels? Concerned that overly stringent Defender requirements may adversely affect the overall Intune MDM user experience.

22:54 – Question – Do you have anything currently available or in development that will act similar to GPresult/RSOP (result set up policy) to see what settings are applied via Intune on a device and what policy applies the setting?

32:03 – Question – In a mixed environment (Entra ID joined + hybrid joined + a few BYOD), what’s your recommended baseline policy stack in Intune + Defender so we avoid overlapping controls and false positives? And how do you decide what belongs in Intune vs Defender?

40:00 – Question – Can we apply a compliance policy for risk level if the computer has Defender but is not in Intune it is manage from different MDM?

44:37 – Question – Can we only use MS Defender for Intune managed devices? What are the prerequisites?

46:05 – Question – So, with Intune, Defender for Cloud/M365, where is the overlap with Purview? As long as your environment is stood up using CAF/WAF with proper management groups that are top down? -- Note for audience -- CAF = Cloud Adoption Framework and WAF = Well-Architected Framework

50:57 – Question – Do you recommend the security baselines in Intune?
AMA: Secure your endpoints with policy and Microsoft DefenderAMA: Managing Windows updatesWindows 365 AMA: Windows AppAsk Microsoft Anything: Secure Boot - December 2025From panic to productive: point-in-time restore in WindowsAMA: Intune device inventory and analytics - Tech Community LiveAMA: Windows 365 - June 2025Transitioning to post-quantum cryptographyWindows settings backup and restore: Faster PC setup and recoveryAMA: The future of AI with Windows 11 and Copilot+ PCsLets talk Windows and Intune: 2026 editionAMA: Copilot/agentic-centered endpoint management
Windows At Work |

AMA: Secure your endpoints with policy and Microsoft Defender

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER