Lolus Posted June 7, 2022 Posted June 7, 2022 We have switched over to Microsoft Defender few years back for our MAT secondary and primary schools. Managing via SCCM which is great. We support a bunch of non MAT primary schools and their Sophos contracts are due renewal. First idea was to just enable and manage Defender via Group Policies (and bin Sophos) but this won't give us full management (threat alerts, status and management of Defender on devices etc). I can't see it as a requirement on RPA insurance documents - so unsure if that would be ok with them if anything happens? I believe there are some 3rd party tools that read devices logs, feed in Defender related events and also manage Defender clients. Any recommendations? ... or perhaps it's cheaper just to pay for Sophos... Thanks
mavhc Posted June 7, 2022 Posted June 7, 2022 Use Windows Event Forwarding to forward the Windows Defender event logs to a central source
TechMonkey Posted June 7, 2022 Posted June 7, 2022 Are they O365 registered? Could be managed from there
CHiLL Posted June 7, 2022 Posted June 7, 2022 I believe if you Intune the devices, you can manage the security from there (though it may require additional licenses).
Lolus Posted June 7, 2022 Author Posted June 7, 2022 Devices are not O365 registered. Schools are on O365 (emails, teams etc) and have only A1 Plus licenses. Might request prices for Intune/Config Manager (some schools might only have around 50 devices in total).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now