Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
02Microsoft Defender for Endpoint9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management0/60 units complete
Learning path 02 · Microsoft Defender for Endpoint

9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management

0%

Study focus

Endpoint readiness

Deploy, onboard, configure, and harden devices with Microsoft Defender for Endpoint.

Investigation and response

Investigate devices and evidence, take response actions, automate remediation, and tune detections.

9 modules · 60 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Deploy the Microsoft Defender for Endpoint environment

Focus: tenant creation, platform support, device onboarding, access control, device groups, and advanced features.
0/10
01 / 10Introduction

Deployment has three connected workstreams: prepare the tenant and network, onboard supported endpoints with an appropriate management method, and apply least-privilege access plus device-group scoping.

Official moduleObjectives and prerequisites
02 / 10Create your environment

The first endpoint settings visit establishes tenant preferences. A Security Administrator can select the data-storage geography, retention, and preview-feature preference. Storage geography cannot be changed later; default retention in the lesson is six months.

The sensor runs as LocalSystem and communicates through WinHTTP. Transparent proxy and WPAD are supported autodiscovery approaches.

Exam takeaway: use the least-privileged administrative role; reserve Global Administrator for emergency scenarios.
Official lessonTenant and network configuration
03 / 10Understand operating system compatibility and features

MDE supports Windows, macOS, Linux, Android, and iOS, but capability depth and deployment tooling differ. macOS includes AV, EDR, and vulnerability management and can be managed through Intune or Jamf. Linux supports AV, EDR, and vulnerability management with command-line and common configuration-management options. Mobile platforms emphasize web protection, anti-phishing, unsafe-connection blocking, and Intune/Conditional Access integration.

Exam takeaway: verify current platform and version prerequisites in the official documentation before designing rollout groups.
Official lessonPlatform compatibility
04 / 10Onboard devices
  1. Configure Device discovery, normally using Standard discovery.
  2. Verify OS and connectivity prerequisites.
  3. Select the platform-specific onboarding package and deployment method.
  4. Deploy through Intune/MDM, Group Policy, Configuration Manager, scripts, or supported third-party tooling.
  5. Run the detection test and confirm sensor reporting.

A local script is intended for limited evaluation, not enterprise-scale rollout. Non-persistent VDI requires its dedicated onboarding approach. Offboarding packages and steps are platform-specific.

Official lesson and simulationOnboarding and offboarding
05 / 10Manage access

RBAC controls both actions and visibility. Roles define allowed capabilities; Microsoft Entra security groups receive roles; device groups define the device data and alerts visible to those users. New MDE customers use Unified RBAC.

Entra roleInitial portal access
Security Administrator / Global AdministratorFull access
Security ReaderRead-only access
Official lessonRBAC and device groups
06 / 10Create and manage roles for RBAC

Create roles under Settings > Endpoints > Permissions, select granular permissions, and assign an existing Entra security group. Permission families include viewing data, active remediation, alert investigation, security settings, vulnerability-management workflows, Intune endpoint security, and basic or advanced Live Response.

Exam takeaway: a role alone is incomplete—associate it with an Entra group and then scope that group to device groups.
Official lessonRole creation and permission families
07 / 10Configure device groups

Device groups organize endpoints by name, domain, tag, or OS. They scope analyst visibility and actions and can apply different automated-remediation levels. When rules overlap, the device belongs to the highest-ranked matching group.

  1. Choose a group name and remediation level.
  2. Define and preview the matching rule.
  3. Grant access to eligible Entra groups with RBAC roles.
  4. Rank the group relative to other groups.
Official lessonGroup matching, scope, and ranking
08 / 10Configure environment advanced features

Advanced features are tenant-level switches. Common examples include Live Response, unsigned Live Response scripts, custom network indicators, Microsoft Intune connection, Microsoft Defender for Cloud Apps integration, web-content filtering, preview features, and device discovery. Enable only capabilities your operational and governance processes support.

Exam takeaway: a feature may require both a tenant switch and separate RBAC, endpoint, licensing, or network prerequisites.
Official lessonAdvanced feature switches
09 / 10Module assessment

Check that you can distinguish tenant settings, platform-specific onboarding, Entra roles, MDE RBAC roles, device groups, and advanced-feature prerequisites.

Official assessmentDeployment knowledge check
10 / 10Summary and resources

Deployment is successful when supported devices are onboarded and reporting, the service can reach required cloud endpoints, access is least-privileged and device-scoped, and advanced capabilities are deliberately enabled.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Endpoint