Intune – You can now configure Microsoft Defender update behaviour (preview)

If use Intune, you know you can manage your devices configuration using configuration profiles.

As part of these profiles, you can configure Microsoft Defender to enable firewall, control antimalware behaviour…

Until now, you were not able to configure Microsoft Defender update behaviour (engine update,platform update and security intelligence update and update channels – beta, current preview, current staged, current broad or critical).

  • Beta – first to receive new update to help identifying and reporting issues
  • Current preview – receive the updates earlier during the monthly gradual release; for use for pre-production/validation
  • Current staged – receive the updates after the monthly gradual release
  • Current broad – receive the updates only after monthly gradual release is completed
  • Critical – receive the updates with a 48-hours delay

These settings are available using either settings catalog or Endpoint security\Antivirus profiles


This applies to both Windows and macOS.

It supports co-managed Windows devices too (requires the use of SCCM version 2006 or later)

Leave a Comment

Your email address will not be published. Required fields are marked *

The reCAPTCHA verification period has expired. Please reload the page.