{"id":7573,"date":"2021-12-16T06:07:20","date_gmt":"2021-12-16T06:07:20","guid":{"rendered":"https:\/\/www.insentragroup.com\/gb\/?p=7573"},"modified":"2022-03-30T08:25:53","modified_gmt":"2022-03-30T08:25:53","slug":"defend-at-all-cost-your-endpoints-need-you","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/gb\/insights\/geek-speak\/secure-workplace\/defend-at-all-cost-your-endpoints-need-you\/","title":{"rendered":"Defend At All cost \u2013 Your Endpoints Need You"},"content":{"rendered":"\n<p>Hey folks! Pure Awesomeness here and I know what you\u2019re thinking\u2026 \u201cwhere on earth have you been with your updates? We\u2019ve been waiting impatiently for the next release!\u201d Well, to tell you the truth, things have been absolute mayhem from trying to keep the kids entertained to working from home to finally sitting down and watching Season 5 of Money Heist. However, I\u2019m back now with all of my energy focused on releasing a new kick a** blog.<\/p>\n\n\n\n<p>For this blog, given the huge focus around all things security and combined with a recent deployment opportunity with a client, I\u2019ve decided to share my wisdom and knowledge on the deployment of Microsoft Defender for Endpoint (let\u2019s be honest, you probably already figured it out from the title of the blog, however, occasionally I like to build up the suspense).<\/p>\n\n\n\n<p>Now before we kick things into gear, you know what you must do:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Grab a cup of that world-famous Arabica infused liquid gold<\/li><li><a href=\"https:\/\/www.insentragroup.com\/gb\/insights\/geek-speak\/fasttrack\/microsoft-fasttrack-zero-trust-and-identity-shifting-the-security-controls\/\" target=\"_blank\" rel=\"noreferrer noopener\">Watch my FastTrack Updates<\/a> and don\u2019t forget to Like\/Share them because social media is now king<\/li><li><a href=\"https:\/\/www.youtube.com\/channel\/UCGN1xKBnZ_p_l-FhWJd6y4A\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Subscribe to Insentra<\/a> on YouTube<\/li><\/ol>\n\n\n\n<p>Now buckle up and enjoy the ride as I take you through the wonder which is Microsoft Defender for Endpoint. Here we go!<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #F37237;color: #F37237\"><span>WHAT IS DEFENDER FOR ENDPOINT?<\/span><\/h3>\n\n\n\n<p>Microsoft couldn\u2019t just stop at Windows Defender. The wizards behind the scenes who have been responsible for building the Microsoft 365 cloud from the infant days of fog or mist to the cumulonimbus it is today (yep, I\u2019m also a Nephrologist \u2013 had to refer to Google on this one), have introduced another portal into the ecosystem. &nbsp;With this portal, you can onboard your devices and it will provide you with a whole bunch of security threat detection insights and remediation tasks to apply. This is Pure Awesomeness\u2019s definition. Microsoft\u2019s definition goes like this &#8211; Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate and respond to advanced threats.<\/p>\n\n\n\n<p>Pretty close if you ask me. Moving on!<\/p>\n\n\n\n<p>So how do I onboard devices into the Defender portal (aka the new security.microsoft.com portal) I hear you ask? Keep reading my loyal apprentice for the answer to said question.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #F37237;color: #F37237\"><span>DEVICE ONBOARDING<\/span><\/h3>\n\n\n\n<p>Ok, so you have a fleet of Windows 10 devices (hopefully running 21H2\u2026if not, <a href=\"mailto:hambik.matsovian@insentragroup.com\">email me separately and let\u2019s talk<\/a>) with Windows Defender preloaded and running as the active AV (of course it is right?). The business has procured M365 E5 licenses and now you want to take advantage of Microsoft Defender for Endpoint. Actually, let\u2019s just call it MDE because let\u2019s face it, we live by acronyms. How do you now onboard the devices? Well, you\u2019ve got a few options available, depending on how you\u2019re managing these Windows 10 devices today.<\/p>\n\n\n\n<p><strong>ConfigMgr<\/strong><\/p>\n\n\n\n<p>If you currently manage your Windows 10 fleet using ConfigMgr and have no intent to move management capabilities into Microsoft Endpoint Manager (or MEM<a> because acronyms<\/a>), firstly, <a href=\"mailto:hambik.matsovian@insentragroup.com\" target=\"_blank\" rel=\"noreferrer noopener\">contact me<\/a> and let\u2019s dive into why you don\u2019t want to use MEM and then only if I\u2019m convinced, you can proceed with step two, which is to create the Endpoint Protection policy directly through ConfigMgr and upload the MDE onboarding package. Don\u2019t stress\u2026I\u2019m about to tell you how to get access to the onboarding package.<\/p>\n\n\n\n<p>Log into the Defender Portal (security.microsoft.com) and then click on Settings \u2013 Endpoints \u2013 Onboarding Select Windows 10 as the operating system and select System Centre Configuration Manager or Microsoft Endpoint Configuration Manager (depending on the version of ConfigMgr you are running) as the deployment method and then click on download.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"466\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img1-1024x466.jpg\" alt=\"\" class=\"wp-image-7575\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img1-1024x466.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img1-300x137.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img1-768x350.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img1.jpg 1146w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Next, in ConfigMgr, navigate to Asset and Compliance \u2013 Overview \u2013 Endpoint Protection \u2013 Microsoft Defender ATP Policies, create a new policy, upload the package file, assign it to your device collection and bingo\u2026devices onboarded! Well not instantly, it\u2019s the public cloud\u2026since when is any change ever instant?<\/p>\n\n\n\n<p>Then, log back into the Defender portal and under Device Inventory, you should see your onboarded devices!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"381\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img2-1024x381.jpg\" alt=\"\" class=\"wp-image-7576\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img2-1024x381.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img2-300x112.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img2-768x286.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img2.jpg 1253w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>I\u2019d usually refer to the Carlton dance for a celebration like this but this time, it\u2019s time for the <a href=\"https:\/\/www.youtube.com\/watch?v=s4sLZOmrvEs\" rel=\"nofollow noopener\" target=\"_blank\">Gru dance<\/a>!<\/p>\n\n\n\n<p>So, that\u2019s onboarding through ConfigMgr. Next up, Intune!<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #F37237;color: #F37237\"><span>INTUNE<\/span><\/h3>\n\n\n\n<p>OK, now I draw your attention to door number two, where your onboarding tasks are completed using Intune. The process is a little different than the ConfigMgr approach and requires the integration between Intune and Defender to be enabled as a prerequisite.<\/p>\n\n\n\n<p>How does the integration get established you say? What kind of blog would this be if I didn\u2019t tell you?<\/p>\n\n\n\n<p>Log into the Defender portal and then click on Settings \u2013 Endpoints \u2013 Advanced Features. Scroll down until you see Microsoft Intune Connection and turn it on. It\u2019s that simple!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"137\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img3-1024x137.jpg\" alt=\"\" class=\"wp-image-7577\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img3-1024x137.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img3-300x40.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img3-768x103.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img3.jpg 1253w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Once it\u2019s turned on, log into the Intune portal and click Endpoint Security \u2013 Microsoft Defender for Endpoint and confirm the connection status shows Available. Once the connection is established, Intune and Defender will synchronise with each other at least once every 24 hours.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"137\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img4-1024x137.jpg\" alt=\"\" class=\"wp-image-7578\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img4-1024x137.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img4-300x40.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img4-768x103.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img4.jpg 1253w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The one thing to note and this is where the onboarding process is different compared to ConfigMgr is once the integration is established between Intune and Defender, Intune receives an onboarding configuration package from MDE, so there\u2019s nothing to download. However, you will need to configure a Configuration Profile for MDE to deploy the package to your Windows devices.<\/p>\n\n\n\n<p>So, since this is a purely awesome blog written by Pure Awesomeness, I\u2019m going to let you know how to configure the profile. To create the Configuration Profile, follow these steps:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on Devices \u2013 Windows \u2013 Configuration Profiles<\/li><li>Click Create Profile and select the following:<ul><li>Platform: Windows 10 and later<\/li><\/ul><ul><li>Profile Type: Microsoft Defender for Endpoint (desktop devices running Windows 10 or later)<\/li><\/ul><ul><li>Click Create<\/li><\/ul><\/li><li>Give the profile an easily identifiable name and click Next<\/li><\/ul>\n\n\n\n<p>Configure the Endpoint Detection and Response (EDR) settings and click Next<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"299\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img5-1024x299.jpg\" alt=\"\" class=\"wp-image-7579\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img5-1024x299.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img5-300x88.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img5-768x224.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img5.jpg 1253w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Assign the profile to a group of devices \u2013 start with a test\/pilot group<\/li><li>Set the Applicability Rules if need be<ul><li>Intune will only apply the profile to devices which meet the combined criteria of these rules<\/li><\/ul><\/li><li>Review the profile settings and click Create<\/li><\/ul>\n\n\n\n<p>Once the profile has been created, you can check the properties to confirm the package type:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"485\" src=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img6-1024x485.jpg\" alt=\"\" class=\"wp-image-7580\" srcset=\"https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img6-1024x485.jpg 1024w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img6-300x142.jpg 300w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img6-768x363.jpg 768w, https:\/\/www.insentragroup.com\/gb\/wp-content\/uploads\/sites\/20\/2021\/12\/Hambik-Matsovian-insentra-blog-1-12162021-img6.jpg 1253w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #F37237;color: #F37237\"><span>DETECTION TEST<\/span><\/h3>\n\n\n\n<p>Finally, once your devices are onboarded, how do you know they\u2019ve been onboarded successfully? Well, Microsoft has kindly provided a detection script which can be run from each onboarded device. So, no more \u201cI\u2019ve onboarded my devices into MDE and given nothing is instant with the public cloud, I need to wait 8 hours for the devices to show up\u201d.<\/p>\n\n\n\n<p>Simply log into the devices you just onboarded and follow the below steps:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Create a folder: C:test-MDATP-test<\/li><li>Open an elevated command-line prompt on the device and run the below script:<ul><li><strong><em>powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = &#8216;silentlycontinue&#8217;;(New-Object System.Net.WebClient).DownloadFile(&#8216;http:\/\/127.0.0.1\/1.exe&#8217;, &#8216;C:\\test-MDATP-test\\invoice.exe&#8217;);Start-Process &#8216;C:\\test-MDATP-test\\invoice.exe&#8217;<\/em><\/strong><\/li><\/ul><\/li><\/ul>\n\n\n\n<p>The command prompt window will close automatically. If successful, the detection test will be marked as completed and a new alert will appear in the portal for the onboarded device in about 10 minutes.<\/p>\n\n\n\n<p>There you have it, folks! A brand new blog by yours truly on a topic I\u2019ve started to dive into more. Stay tuned for additional releases on the beast which is MDE.<\/p>\n\n\n\n<p>Until next time, Pure Awesomeness signing off!<\/p>\n\n\n\n<p><em><strong>\u201cMany of life&#8217;s failures are people who did not realise how close they were to success when they gave up\u201d &#8211; Thomas A. Edison<\/strong><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hey folks! Pure Awesomeness here and I know what you\u2019re thinking\u2026 \u201cwhere on earth have you been with your updates? We\u2019ve been waiting impatiently for the next release!\u201d<\/p>\n","protected":false},"author":52,"featured_media":7574,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[20],"tags":[233,232,231,58,132,59,60,107,134,96],"class_list":["post-7573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-workplace","tag-config-manager","tag-configmgr","tag-endpoint-security","tag-it-security","tag-m365","tag-microsoft","tag-microsoft-365","tag-microsoft-defender","tag-microsoft-fast-track","tag-windows-10","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/7573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/comments?post=7573"}],"version-history":[{"count":2,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/7573\/revisions"}],"predecessor-version":[{"id":8903,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/7573\/revisions\/8903"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/media\/7574"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/media?parent=7573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/categories?post=7573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/tags?post=7573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}