{"id":2809,"date":"2023-02-22T14:11:10","date_gmt":"2023-02-22T14:11:10","guid":{"rendered":"https:\/\/modern-workplace.uk\/?p=2809"},"modified":"2023-03-07T11:37:49","modified_gmt":"2023-03-07T11:37:49","slug":"teams-virtual-sbc-closing-azure-network-ports-warnings-for-azureloadbalancer-and-virtualnetwork-2-2-2-2-3-2-3-2-2-2-2-2-3-2-2-3-2-3-2-2-2-3-2-2-2-2","status":"publish","type":"post","link":"https:\/\/modern-workplace.uk\/?p=2809","title":{"rendered":"Do my Android Devices (Registered in Intune) have Microsoft Defender for Endpoint Installed?"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<p>To make Microsoft 365 administrators&#8217; life easier, it is possible to deploy Defender for Endpoint (Defender) on Android devices registered on Microsoft Endpoint Manager (Intune) as you can see here <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/android-intune?view=o365-worldwide\">Deploy Microsoft Defender for Endpoint on Android with Microsoft Endpoint Manager | Microsoft Learn<\/a>).<\/p>\n\n\n\n<p>However, what is missing is a report that unifies the information stored in Intune and the ones in Defender, so that is possible to understand how many Intune registered devices are still missing the Defender deployment.<\/p>\n\n\n\n<p>The Intune portal gives you an export of the registered Android devices<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Intune_Export_Blog01_60-1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"632\" height=\"232\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Intune_Export_Blog01_60-1.jpg\" alt=\"\" class=\"wp-image-2815\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Intune_Export_Blog01_60-1.jpg 632w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Intune_Export_Blog01_60-1-300x110.jpg 300w\" sizes=\"auto, (max-width: 632px) 100vw, 632px\" \/><\/a><\/figure>\n\n\n\n<p>The Defender portal gives you an export of all the devices<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01-1024x219.jpg\" alt=\"\" class=\"wp-image-2811\" width=\"625\" height=\"133\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01-1024x219.jpg 1024w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01-300x64.jpg 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01-768x164.jpg 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog01.jpg 1086w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/a><\/figure>\n\n\n\n<p>However, the Defender export does not give you any ID number that you can use to match with the Intune export.<\/p>\n\n\n\n<p>Digging into the Defender reports, at a single device level, you will see a &#8220;Device AAD id&#8221; value. That could be an useful link to the Intune report that has an &#8220;Azure AD Device ID&#8221;. However the Defender export does not give you this information<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog02.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog02.jpg\" alt=\"\" class=\"wp-image-2812\" width=\"303\" height=\"336\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog02.jpg 465w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2023\/02\/Defender_Export_Blog02-270x300.jpg 270w\" sizes=\"auto, (max-width: 303px) 100vw, 303px\" \/><\/a><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Time for GitHub<\/p>\n\n\n\n<p>Time to use the Microsoft Defender for Endpoint PowerShell module. It is (quoting the GitHub page) &#8220;a collection of easy-to-use cmdlets and functions designed to make it easy to interface with the Microsoft Defender for Endpoint API&#8221;.<\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/alexverboon\/PSMDATP\">GitHub &#8211; alexverboon\/PSMDATP: PowerShell Module for managing Microsoft Defender Advanced Threat Protection<\/a><\/p>\n\n\n\n<p>The module requires the registration of an app in the Azure portal and assigning permissions. <\/p>\n\n\n\n<p>When everything is in place, just run the following command (exporting to your favourite folder)<\/p>\n\n\n\n<p><code>Get-MDATPDevice -All -Verbose | Export-Csv c:\\script\\DefenderExport.csv<\/code><\/p>\n\n\n\n<p>Now you can match the information from Defender (using the aadDeviceId in the DefenderExport.csv file) with the export you did from Intune (using the &#8220;Azure AD Device ID&#8221; value) using your favourite tool (I was comfortable with Excel)<\/p>\n\n\n\n<p>All the devices in the Intune export not listed in the Defender export require some attention \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How do you check how many Intune registered Android devices are still missing the Defender deployment?<br \/>\nFollow the steps here to find this information.<br \/>\nTo give a bit of background: it is possible to deploy Defender for Endpoint (Defender) on Android devices registered on Microsoft Endpoint Manager (Intune) as you can see here Deploy Microsoft Defender for Endpoint on Android with Microsoft Endpoint Manager | Microsoft Learn).<br \/>\nHowever, there is no report that unifies the information stored in Intune and the ones in Defender.<\/p>\n","protected":false},"author":1,"featured_media":2818,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[810,753,757],"tags":[762,11,812,813,811,768,759,77],"class_list":["post-2809","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-810","category-microsoft365","category-office-365","tag-microsoftteams","tag-android","tag-defender","tag-defender-for-endpoint","tag-endpoint-manager","tag-intune","tag-microsoft-365","tag-office-365"],"_links":{"self":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2809"}],"version-history":[{"count":2,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2809\/revisions"}],"predecessor-version":[{"id":2819,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2809\/revisions\/2819"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/media\/2818"}],"wp:attachment":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}