Microsoft Endpoint Administrator — Question 187
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender for Endpoint on the computers.
You need to prevent users from disabling Microsoft Defender for Endpoint.
What should you do?
Answer options
- A. From the Microsoft Intune admin center, create a security baseline.
- B. From the Microsoft Intune admin center, create an antivirus policy.
- C. From the Microsoft Entra admin center, create a Conditional Access policy.
- D. From the Microsoft Intune admin center, create a device compliance policy.
Correct answer: B
Explanation
The correct answer is B because creating an antivirus policy in Microsoft Intune allows you to configure settings that can prevent users from disabling Microsoft Defender for Endpoint. Option A, while useful for overall security, does not specifically address the disabling of Defender. Option C pertains to access control and does not manage antivirus settings, and option D focuses on compliance rather than directly managing antivirus capabilities.