An overview of MDE deployment
As you learned in the previous chapter, MDE is part of Microsoft 365 Defender, the wider XDR platform. You also learned that MDE provides both pre- and post-incident capabilities, insofar as it can harden and defend systems against malware and abuse, as well as use telemetry and machine learning to identify when something looks like an attack after the fact. Let’s explore how this translates into your administrative use and deployment of MDE.
Onboarding
In the chapters that follow this one, you will find guidance on how to onboard devices to MDE. This is a deep topic that will be explored thoroughly in those chapters, though an overview to get started is required.
What does onboarding mean, strictly speaking? Onboarding means getting the device to transmit EDR telemetry to the service and present itself in the Microsoft 365 Defender portal at security.microsoft.com (also known as the Microsoft Defender Security Center).
Onboarding for...