Skip to main content

Setting Up Microsoft Defender for Business (Step-by-Step)

A practical guide to deploying Microsoft Defender for Business across your organisation. Covers onboarding devices, configuring policies, and monitoring threats.

6 min readUpdated March 29, 2026

Overviewsection

Microsoft Defender for Business is an endpoint security solution built specifically for small and medium businesses (up to 300 users). It includes endpoint detection and response (EDR), automated investigation, threat and vulnerability management, and attack surface reduction — capabilities that previously required an E5 licence.

Defender for Business is included with Microsoft 365 Business Premium or available as a standalone add-on.

Prerequisitessection

  • Microsoft 365 Business Premium, E3 + Defender for Business add-on, or E5 licence
  • Global Admin or Security Admin role
  • Devices running Windows 10/11 Pro, Enterprise, or Education
  • macOS, iOS, and Android are also supported

Step 1: Open the Setup Wizardsection

  1. Go to security.microsoft.com (Microsoft Defender XDR portal)
  2. If this is your first time, the Setup wizard will launch automatically
  3. If not, go to Settings > Endpoints > Onboarding

The wizard walks through:

  • Assigning user permissions
  • Setting up email notifications for alerts
  • Onboarding your first devices

Step 2: Onboard Devicessection

If your devices are enrolled in Intune, onboarding is automatic:

  1. Go to intune.microsoft.com > Endpoint security > Microsoft Defender for Endpoint
  2. Toggle Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations to On
  3. Toggle Connect Windows devices to On
  4. Devices will onboard automatically within hours

Windows devices via local script (for non-Intune environments)section

  1. Go to security.microsoft.com > Settings > Endpoints > Onboarding
  2. Select Local Script as the deployment method
  3. Download the onboarding package
  4. Run on each device as Administrator:
powershell
# Extract and run the onboarding script
Expand-Archive -Path "WindowsDefenderATPOnboardingPackage.zip" -DestinationPath "C:\Temp\MDE"
& "C:\Temp\MDE\WindowsDefenderATPLocalOnboardingScript.cmd"

Verify onboardingsection

powershell
# Check Defender for Endpoint service status
Get-Service -Name "Sense" | Select-Object Status, StartType
# Should show: Running, Automatic

Or check in the portal: security.microsoft.com > Assets > Devices — the device should appear within 5-10 minutes.

macOS devicessection

  1. In the Defender portal, go to Settings > Endpoints > Onboarding
  2. Select macOS as the operating system
  3. Download the onboarding package
  4. Deploy via Intune or install manually using the .pkg installer

Mobile devices (iOS / Android)section

Deploy Microsoft Defender via Intune app deployment:

  1. Go to intune.microsoft.com > Apps > All apps > Add
  2. Select Microsoft Defender for the appropriate platform
  3. Assign to your user groups

Step 3: Configure Security Policiessection

Default policies (automatic)section

Defender for Business comes with pre-configured policies that are suitable for most SMBs:

PolicyWhat It DoesDefault
Next-generation protectionReal-time antivirus, cloud protection, behaviour monitoringEnabled
Firewall protectionWindows Firewall rules for all profilesEnabled
Attack surface reductionBlocks common attack techniques (Office macros, scripts, etc.)Audit mode
Endpoint detection and responseContinuous monitoring for advanced threatsEnabled

Customise policiessection

To adjust policies:

  1. Go to security.microsoft.com > Endpoints > Configuration management > Device configuration
  2. Click the policy you want to edit
  3. Common adjustments:
    • Move ASR rules from Audit to Block after reviewing audit results for 1-2 weeks
    • Add folder exclusions for line-of-business applications that trigger false positives
    • Adjust scan schedules to run outside business hours
Warning

Do not disable cloud-delivered protection or tamper protection. These are critical for detecting zero-day threats and preventing malware from turning off Defender.

Step 4: Configure Alerts and Notificationssection

  1. Go to security.microsoft.com > Settings > Endpoints > Email notifications
  2. Click Add notification rule
  3. Configure:
    • Name: Critical Alerts — IT Team
    • Severity: High and Critical
    • Recipients: your IT team email or distribution group
  4. Also configure alerts in Settings > Endpoints > Alert notifications for specific detection categories

Step 5: Review the Security Dashboardsection

After onboarding devices, your main monitoring views are:

Threat and Vulnerability Managementsection

security.microsoft.com > Vulnerability management > Dashboard

This shows:

  • Exposure score — how vulnerable your environment is (lower is better)
  • Microsoft Secure Score for Devices — how well your devices are configured
  • Top security recommendations — prioritised actions to reduce risk
  • Vulnerable software — applications with known CVEs installed on your devices

Incidents and Alertssection

security.microsoft.com > Incidents & alerts

This shows correlated security events. Each incident groups related alerts, affected devices, and users into a single investigation view. Defender automatically investigates many alerts and takes remediation actions.

Device Inventorysection

security.microsoft.com > Assets > Devices

Shows all onboarded devices with their:

  • Risk level (High, Medium, Low)
  • Exposure level
  • OS version and health status
  • Last seen timestamp

Step 6: Enable Automated Investigation and Responsesection

Defender for Business includes automated investigation that can quarantine files, block malicious processes, and remediate threats without manual intervention.

  1. Go to security.microsoft.com > Settings > Endpoints > Advanced features
  2. Ensure Automated Investigation is set to On
  3. Set the automation level to Full - remediate threats automatically for most environments
Tip

Full automation is recommended for SMBs because most businesses do not have a dedicated SOC team to manually triage every alert. Defender's automated investigation resolves the majority of common threats correctly.

Monitoring Checklist (Weekly)section

TaskWhereWhat to Look For
Review incidentsIncidents & alertsAny High/Critical incidents not auto-resolved
Check device healthAssets > DevicesDevices showing as "Inactive" or "Misconfigured"
Review recommendationsVulnerability managementTop 5 recommendations, especially critical CVEs
Check Secure ScoreVulnerability management > DashboardScore trending up, not down
Review web content filteringReports > Web protectionBlocked categories and URLs

Troubleshootingsection

IssueCauseFix
Device not appearing in portalOnboarding not complete or Sense service stoppedRe-run onboarding script, check Get-Service Sense
"Onboarding failed" errorProxy blocking communication to Microsoft endpointsAllow *.securitycenter.windows.com and *.endpoint.security.microsoft.com
High number of false positivesASR rules or antivirus flagging legitimate appsAdd exclusions for specific apps/paths in the policy
Automated remediation not workingAutomation level set to "No automated response"Change to "Full" in Settings > Advanced features
macOS device shows "No sensor data"Defender not granted Full Disk AccessGrant in System Settings > Privacy & Security > Full Disk Access

Next Stepssection

  • Enable web content filtering to block malicious and inappropriate websites
  • Configure device groups to apply different policies to different teams
  • Integrate with Microsoft Sentinel for advanced SIEM capabilities (larger organisations)
  • Review the Secure Score recommendations monthly and implement the top priorities

Need help with ongoing endpoint security?section

Explore managed IT support for device administration and security management. If you already use CyberITEX security operations, read about the Microsoft Defender integration.

Microsoft DefenderEndpoint SecurityMicrosoft 365EDRSmall Business

Was this article helpful?