Configuration management considerations
Though we handled configuration management selection in detail in Chapter 5, Planning and Preparing for Deployment, we’ll go ahead and discuss some of the finer points here to add additional context for consideration, especially if you’re thinking about adding a net new configuration management approach.
At a high level, each possible configuration tool consists of three elements that will allow you to create a policy object, send it to the device, and apply it, at which point Defender picks it up:
- A template in an admin interface
- A management channel (service and client combination)
- A client-side interface/API
The following diagram shows a typical flow that illustrates how configuration is performed:
Figure 6.5 – Typical MDE management flow
While the best configuration management experience for MDE is arguably provided through the Intune Unified Endpoint Management...