Endpoint security in Intune Overview Flashcards
(43 cards)
What are the 8 high level categories in the Endpoint security node?
- Overview
- All devices
- Security baselines
- Security tasks
- Manage
- Monitor
- Set up
- Help and support
What is the default page when opening the Endpoint security node in Microsoft Intune admin center?
Overview page
What does the endpoint security Overview page present?
A consolidated dashboard with displays and information from focused nodes of endpoint security
in Overview, what information does the Defender for Endpoint Connector status view display?
Current status for the tenant-wide Defender for Endpoint Connector
in Overview, what is the purpose of the label in the Defender for Endpoint Connector status view?
Serves as a link to open the Microsoft Defender for Endpoint portal
in Overview, what does the table for Windows devices onboarded to Defender for Endpoint show?
Tenant-wide status for endpoint detection and response (EDR) onboarding, with counts of devices that are and aren’t onboarded
in Overview, what does the label in the Windows devices onboarding table link to?
Opens the Summary tab of the Endpoint detection and response policy node
in Overview, what does the link ‘Deploy preconfigured policy’ do?
Opens the policy node for Endpoint detection and response to deploy a policy
in Overview, what does the link ‘Onboard devices to Defender for Endpoint’ open?
Opens the Defender portal for additional onboarding steps outside of Intune’s workflow
Where can the Antivirus agent status report be found in the Intune admin center?
Reports > Microsoft Defender Antivirus on the Summary tab
in Overview, what additional reports are included in the Other Monitoring reports section?
Tiles that open additional Microsoft Defender Antivirus reports, including Detected Malware Firewall Status
in Overview, what does another tile in the Other Monitoring reports section open?
Opens the Defender portal to view sensor and antivirus health data
What does the All devices view in the Endpoint security node include?
A list of all devices from your Microsoft Entra ID available in Microsoft Intune
The All devices view allows for detailed inspection of each device.
What can you do from the All devices view in the Endpoint security node?
Select devices to drill in for more information
This feature facilitates a deeper understanding of device details and statuses.
What are security baselines in Intune?
Preconfigured groups of Windows device configuration settings with best practice recommendations from Microsoft security teams
Security baselines are designed to simplify the management of security settings on devices.
Which device settings do security baselines in Intune support?
Windows device settings, Microsoft Edge, Microsoft Defender for Endpoint Protection, and more
This support helps ensure consistency and security across different platforms.
What is the purpose of security baselines in Intune?
To configure device configuration settings based on best practice recommendations
They help streamline the security management process.
Why is it important to understand other methods of configuring devices when using security baselines?
To avoid conflicts between different configuration settings
Conflicts can lead to security vulnerabilities or operational issues.
True or False: Security baselines are the only method available in Intune for configuring device settings.
False
Intune offers several methods for configuration beyond security baselines.
Fill in the blank: Security baselines in Intune are preconfigured groups of _______.
Windows device configuration settings
These settings are aligned with best practices.
Where can you configure security baselines?
Go to Endpoint security > Security baselines
What is the purpose of integrating Intune with Microsoft Defender for Endpoint?
To review Security tasks that identify at-risk devices and provide steps to mitigate that risk.
This integration allows for effective communication between security teams to manage vulnerabilities.
Who determines which devices are at risk in the integration process?
The Microsoft Defender for Endpoint team.
They assess the security posture and communicate findings to the Intune team.
What information do Security tasks created by the Microsoft Defender for Endpoint team include?
The devices at risk, the vulnerability, and guidance on how to mitigate that risk.
This helps streamline the remediation process for Intune admins.