Skip to Content

EDR Policies

Endpoint Detection and Response (EDR) policies configure Microsoft Defender for Endpoint onboarding and telemetry settings. Deploy EDR policies through Intune to enable advanced threat detection.

Onboarding Configuration

Windows

SettingDescription
Onboarding PackageAuto-deployed through Intune
Sample SharingAll / Safe only / None
Telemetry FrequencyNormal / Expedited
OffboardingRemove from MDE monitoring

macOS

  • Onboarding blob via configuration profile
  • Sample sharing through preference file
  • Network protection for web content filtering

Linux

  • Script-based onboarding
  • Managed configuration
  • Detection and response telemetry

Creating an EDR Policy

  1. Navigate to Endpoint Security then EDR
  2. Select target platform
  3. Configure onboarding settings
  4. Set sample sharing preferences
  5. Configure telemetry level
  6. Assign to device groups

Sample Submission Settings

SettingDescription
Send all samplesMaximum coverage
Send safe samplesNon-personal files only
Always promptUser approval required
Never sendNo samples submitted

Offboarding

Remove devices from MDE monitoring. Deploy offboarding profile. Device stops sending telemetry. Historical data retained.

Status Monitoring

  • Onboarded — Actively reporting to MDE
  • Pending — Onboarding in progress
  • Failed — Onboarding failed
  • Offboarded — Removed from monitoring
  • Not Configured — No EDR policy assigned

Best Practices

  • Onboard all managed devices
  • Use expedited telemetry during investigations
  • Enable automatic sample submission
  • Monitor for failed onboarding
  • Combine with compliance policies using MDE risk signals

API Reference

  • GET /api/devices/security/edr/status — Get onboarding status
  • POST /api/devices/security/edr/policies — Create EDR policy
  • GET /api/devices/security/edr/policies/:id/status — Get deployment status
  • POST /api/devices/security/edr/offboard — Deploy offboarding
Last updated on