Offboard devices using Group Policy:
-
Get the offboarding package from the Microsoft 365 Defender portal:
-
In the navigation pane, select Settings > Endpoints > Device management > Offboarding.
-
Select the operating system.
-
In the Deployment method field, select Group policy.
-
Click Download package and save the .zip file.
-
-
Extract the contents of the .zip file to a shared, read-only location that can be accessed by the device. You should have a file named WindowsDefenderATPOffboardingScript_valid_until_YYYY-MM-DD.cmd.
-
Open the Group Policy Management Console (GPMC), right-click the Group Policy Object (GPO) you want to configure and click Edit.
-
In the Group Policy Management Editor, go to Computer configuration, then Preferences, and then Control panel settings.
-
Right-click Scheduled tasks, point to New, and then click Immediate task.
-
In the Task window that opens, go to the General tab. Choose the local SYSTEM user account (BUILTIN\SYSTEM) under Security options.
-
Select Run whether user is logged on or not and check the Run with highest privileges check-box.
-
In the Name field, type an appropriate name for the scheduled task (for example, Defender for Endpoint Deployment).
-
Go to the Actions tab and select New.... Ensure that Start a program is selected in the Action field. Enter the UNC path, using the file server's fully qualified domain name (FQDN), of the shared WindowsDefenderATPOffboardingScript_valid_until_YYYY-MM-DD.cmd file.
-
Select OK and close any open GPMC windows.
Offboard devices using System Center 2012 R2 Configuration Manager
-
Get the offboarding package from Microsoft 365 Defender portal:
- In the navigation pane, select Settings > Endpoints > Device management > Offboarding.
- Select Windows 10 or Windows 11 as the operating system.
- In the Deployment method field, select System Center Configuration Manager 2012/2012 R2/1511/1602.
- Select Download package, and save the .zip file.
-
Extract the contents of the .zip file to a shared, read-only location that can be accessed by the network administrators who will deploy the package. You should have a file named WindowsDefenderATPOffboardingScript_valid_until_YYYY-MM-DD.cmd.
-
Deploy the package by following the steps in the Packages and Programs in System Center 2012 R2 Configuration Manager article.
Offboard and monitor devices using Mobile Device Management tools
-
Get the offboarding package from Microsoft 365 Defender portal:
-
In the navigation pane, select Settings > Endpoints > Device management > Offboarding.
-
Select Windows 10 or Windows 11 as the operating system.
-
In the Deployment method field, select Mobile Device Management / Microsoft Intune.
-
Click Download package, and save the .zip file.
-
-
Extract the contents of the .zip file to a shared, read-only location that can be accessed by the network administrators who will deploy the package. You should have a file named WindowsDefenderATP_valid_until_YYYY-MM-DD.offboarding.
-
Use the Microsoft Intune custom configuration policy to deploy the following supported OMA-URI settings.
- OMA-URI: ./Device/Vendor/MSFT/WindowsAdvancedThreatProtection/Offboarding
- Date type: String
- Value: [Copy and paste the value from the content of the WindowsDefenderATP_valid_until_YYYY-MM-DD.offboarding file]
Offboard devices using a local script
-
Get the offboarding package from Microsoft 365 Defender portal:
- In the navigation pane, select Settings > Endpoints > Device management > Offboarding.
- Select Windows 10 or Windows 11 as the operating system.
- In the Deployment method field, select Local Script.
- Click Download package and save the .zip file.
-
Extract the contents of the .zip file to a shared, read-only location that can be accessed by the devices. You should have a file named WindowsDefenderATPOffboardingScript_valid_until_YYYY-MM-DD.cmd.
-
Open an elevated command-line prompt on the device and run the script:
-
Go to Start and type cmd.
-
Right-click Command prompt and select Run as administrator.
-
-
Type the location of the script file. If you copied the file to the desktop, type: %userprofile%\Desktop\WindowsDefenderATPOffboardingScript_valid_until_YYYY-MM-DD.cmd
-
Press the Enter key or click OK.
Offboard Windows servers
You can offboard Windows Server 2012 R2, Windows Server 2016, Windows Server (SAC), Windows Server 2019, Windows Server 2019 Core edition in the same method available for Windows 10 client devices.
- Offboard devices using Group Policy
- Offboard devices using Configuration Manager
- Offboard and monitor devices using Mobile Device Management tools
- Offboard devices using a local script
For other Windows server versions, you have two options to offboard Windows servers from the service:
- Uninstall the MMA agent
- Remove the Defender for Endpoint workspace configuration
Onboarding and offboarding policies must not be deployed on the same device at the same time, otherwise this will cause unpredictable collisions.
Source URL: Click here
Comments
0 comments
Please sign in to leave a comment.