Prevant Offboard Devices get ip from DHCP Server

Rodriguez_591 20 Reputation points
2024-08-24T09:09:07.8366667+00:00

Hi,

There is a way to prevent offboard device or non-compliance device to get ip from dhcp server?

Even add the mac address to deny list when there is a non-compilance device (on the computer is not installed microsoft defender for endpoint)

I would love a solution!

Rodriguez_591

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
163 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,048 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 48,581 Reputation points Microsoft Vendor
    2024-08-26T01:42:04.6433333+00:00

    @Rodriguez_591, Thanks for posting in Q&A. Based on my researching, it seems the setting "Block unicast responses to multicast broadcasts" of Firewall under Endpoint security or Endpoint Protection in Intune can block getting IP from DHCP. You can choose one device to test to try this.

    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10

    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-firewall-profile-settings

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Rodriguez_591 20 Reputation points
    2024-08-26T09:09:56.1333333+00:00

    Hi,

    Thanks for response.

    it's possible to do this as an automatically action for non-compliance/offboard devices?

    in Microsoft Intune or Microsoft Defender for Endpoint? when if the Microsoft Defender for Endpoint is not installed in endpoint then there is automatic execution.

    I very, very much hope that there is a solution for this.

    Rodriguez_591


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.