Your Azure AD-joined Windows 11 Enterprise multi-session session hosts are enrolled in Microsoft Intune. You must centrally enforce Microsoft Defender Antivirus settings and also deploy several custom security-related registry values. Which two Intune policy types should you use? Each correct answer presents part of the solution.
Choose an answer
Tap an option to check your answer.
Correct answer: Endpoint security policy for Antivirus (Windows 10 and later), Device configuration profile using Settings catalog (Windows 10 and later).
Why this is the answer
To centrally enforce Microsoft Defender Antivirus settings, use an Endpoint security policy for Antivirus. This policy type is specifically designed for managing security features like antivirus protection on Windows devices. To deploy custom security-related registry values, use a Device configuration profile with the Settings catalog. The Settings catalog allows you to configure a wide range of device settings, including custom registry keys, by providing a comprehensive list of available settings. Device compliance policies are used to define conditions that devices must meet to be considered compliant, often used with Conditional Access, but not for directly deploying settings. Windows Update rings manage update deployment, not antivirus or custom registry settings. Enrollment status page policies configure the user experience during device enrollment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed