Preview Feature - Manage Server Security with Intune!

  Рет қаралды 4,336

Dean Ellerby MVP

Dean Ellerby MVP

Күн бұрын

Пікірлер: 36
@Timmy-Hi5
@Timmy-Hi5 Жыл бұрын
08:00 "It might me important, sounds important to me" 😁😂🤣You made my Friday 😂🤣😁 super funny ... of course you must know what that "slider" do 🤣😅 /me think creating chaos for Admins is Dean's favourite Friday task🤣🤣
@gerardmoore4973
@gerardmoore4973 Жыл бұрын
Great video does this work to get a Windows Server co-managed with intune and configuration management ?
@blablablablaaaaa
@blablablablaaaaa Жыл бұрын
Dean, this is great, thanks! But where did you find out about this change? I didn't see in the Defender Blog, the 'What's New In Defender' page, so obviously I'm missing some channel for getting informed about updates! EDIT: just saw the comment below - thanks!
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
You're welcome ! Thanks for the feedback.
@on_spikes6867
@on_spikes6867 Жыл бұрын
Is "Security settings management" really neccessary to push MDE config from Intune to Servers? if im not mistaken you can onboard servers with Arc to defender for cloud and then enable the connection from MDC to MDE and then any policy from intune gets applied to the servers through Arc?
@on_spikes6867
@on_spikes6867 Жыл бұрын
nevermind, you mentioned it in the intro...
@lasolution365
@lasolution365 Жыл бұрын
The update from Microsoft is that this feature is delayed to early July now.
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
So it’s no longer in Public Preview?
@aranbillen5954
@aranbillen5954 5 ай бұрын
Hi, thank you for this! I cant get the server to show in intune or azure ad only in devices within the defender portal, I have enabled requirements in the connectors / token area I check the server in defender portal and it still states: The device isn’t enrolled to MDE security settings management, verify it complies with pre-requisites and that it is in scope for the feature in the MDE Settings.
@Kongcecil
@Kongcecil Жыл бұрын
Real-time Protection and Cloud-Delivered protection is also locked by Tamper Protection when the device is onboarded, so I Guess you can't be sure that the MDE-Security Settings actually worked in this example? Right? Thanks for the video :-)
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
Yes - you have a great point. The 'proof' I showed isn't actually proof that it worked at all :-)
@cyphernz
@cyphernz Жыл бұрын
sounds good, link to the news of this update? i can't find anything
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
www.linkedin.com/pulse/manage-windows-servers-defender-endpoint-intune-dean-ellerby?
@chadglass4498
@chadglass4498 Жыл бұрын
Does this work for GCC customers as well?
@SophosDefender
@SophosDefender Жыл бұрын
Does ASR work with this method?
@on_spikes6867
@on_spikes6867 Жыл бұрын
no
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
Yep
@alQamar79
@alQamar79 Жыл бұрын
Wonder why they bother with cmd and cscript instead of PowerShell?
@tonypark2710
@tonypark2710 Жыл бұрын
Does this also work for Windows servers that are not VMs generated in Azure?
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
Yep!
@NitinRNtini
@NitinRNtini Жыл бұрын
Yes, as long as they are enrolled and managed by MDE, they will show up in Intune. You can verify this by going to the device details where you will see “Managed by MDE” and “MDE Enrollment:success”.
@Al-eo3sh
@Al-eo3sh 8 ай бұрын
Does this work on server core?
@waleedhaddad5448
@waleedhaddad5448 Жыл бұрын
I have an on-prem server that I am trying to get Defender for server installed. I have successfully connected several servers via Arc and was able to install MDE successfully. However I have several servers that will not connect. Many of them are server 2016. When I try to allow install MDE I receive the following error "Defender for endpoint failed to register to AAD due to an AAD connect Misconfiguration." Has anyone dealt with this and have a solution?
@cyphernz
@cyphernz Жыл бұрын
For the life of me cant get this working on a 2019 domain controller. Server is onboarded but doesnt show in Intune or AAD
@cyphernz
@cyphernz Жыл бұрын
Update: confirmed from MS this is not supported for DCs
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
Seems so! How annoying 😟
@cyphernz
@cyphernz Жыл бұрын
@@DeanEllerbyMVP yeh. Oh well ill continuen to use GPO to manage AV settings on DCs. But Intune for all other servers
@cyphernz
@cyphernz Жыл бұрын
Also, this works for SMBs using Defender for Business Server licensing
@alQamar79
@alQamar79 Жыл бұрын
Check the Onboarding Script seems they rely on local Groups which they don't have so they would actually use Groups in ADDS of the computers OU but not what the script would be doing.
@Timmy-Hi5
@Timmy-Hi5 Жыл бұрын
one Server only ?? how you would recommend the eastated of 12000 servers 😁... in our environment "Mission Impossible" so we will stick with 3rd party
@DeanEllerbyMVP
@DeanEllerbyMVP Жыл бұрын
How did you onboard the 12,000 you currently have? The procedure would probably be of similar scale and complexity? If I had 12,000 servers in my lab, I’d be broke 😀
@Timmy-Hi5
@Timmy-Hi5 Жыл бұрын
@@DeanEllerbyMVP you can't be, MVP broke 😁😂.. impossible 😁..
@Anonymoussssss-r7b
@Anonymoussssss-r7b 5 ай бұрын
You will of course use Arc on management group level or direct onboarding in MDC if it’s already deployed as a vm in azure. That’s what recommended if you want to scale up and cover multiple servers. Then after the onboarding decide if you want to enforce security mgmt capabilities from intune with the mdc connection in MDE portal settings. So my question to you is: Why use third party when the procedure and the complexity still remains?
@liskeard100
@liskeard100 9 ай бұрын
Opoi
Windows Autopilot V2? Or just a new profile type? Who cares! It's here!
12:11
Microsoft Intune From Zero to Hero
39:08
Andy Malone MVP
Рет қаралды 230 М.
She's very CREATIVE💡💦 #camping #survival #bushcraft #outdoors #lifehack
00:26
How it feels when u walk through first class
00:52
Adam W
Рет қаралды 24 МЛН
360 Programming in a Virtual Environment
1:02:54
Out & Equal Workplace Advocates
Рет қаралды 15
Platform Single Sign-On
57:48
MacSysAdmin Conference
Рет қаралды 3,8 М.
The ONLY tool you need for Microsoft Intune app management
15:49
Dean Ellerby MVP
Рет қаралды 5 М.
Get started with Microsoft 365 Administrative Units
18:02
Andy Malone MVP
Рет қаралды 5 М.
Microsoft Intune Role Based Access Control (RBAC) and Scope Tags
17:55
Microsoft Defender for Endpoint on Servers Explained
3:25
Dean Ellerby MVP
Рет қаралды 825
She's very CREATIVE💡💦 #camping #survival #bushcraft #outdoors #lifehack
00:26