Issue with some Microsoft Defender SmartScreen settings missing under Endpoint Security in Intune


There are multiple ways of configuring Microsoft Defender SmartScreen settings in Intune. You can use the Device configuration, custom CSPs, Endpoint Security or even custom Powershell scripts. Microsoft recommends using Endpoint Security to configure device security policies on your endpoints. This is because the policies are specially focused around device security thus keeping the settings relevant. However, not all security settings are covered under Endpoint Security and this became evident while configuring SmartScreen.

In order to configure SmartScreen, you enable the settings under Endpoint Security->Web Protection as shown below.


While this does enable the SmartScreen, it does not configure all the way as users are allowed to disable the option if they like (That is the last thing you want).

Also, there is no setting to enable SmartScreen for IE if you are using Endpoint Security profiles. To get around this, you will need to deploy some additional settings using Device configuration profiles or scripts. I chose to use the built-in functionality and utilize Settings Catalog to deploy the following additional configurations.



Please note that there are ton of other settings, but I am only deploying specific settings according to my requirements. 

After a device sync, all was good.

On Edge, Microsoft Defender SmartScreen showed greyed out and managed.


Same on IE11.



Windows Security also showed SmartScreen for Microsoft Edge as greyed out and managed.


You can monitor the status on Intune as well.


I did notice error code 65000 with one of the settings initially, but it cleared up after a while. However, if you continue to experience the error, then Rudyooms has written an excellent blog on how to fix this. Alternatively, you have the option to configure these settings using Device Configuration profiles instead.

References

Comments

  1. Well stated, you have furnished the right information that will be useful to everybody. Thank you for sharing your thoughts. Cyber Security measures protect your company not only from data breaches, but also from excessive financial losses, a loss of people's trust, and potential risks to brand reputation and future benefits.
    AMC services in Bangalore
    Cyber Security Service Provider
    SIEM Service Provider
    Penetration Testing Company
    IT infrastructure services in Bangalore
    Cloud Service Provider in Bangalore

    ReplyDelete

Post a Comment

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Intune: UAC Elevation Prompt Behavior for Standard Users