How to remove all files for MDE (Microsoft Defender for Endpoint) using Intune after offboarding script is run.

Phil Crombie 0 Reputation points
2025-04-10T10:41:15.3666667+00:00

Hi, we have Windows and Mac Clients with Microsoft Defender for Endpoint.
Intune deploys it to the Windows and Jamf to the Macs.
If we download the offboarding scripts and run them, all the program files are left behind.

Is there an easy way using intune/jamf to remove the application so its not taking up disk space etc?

Thanks in advance

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
491 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Blake Morrison 10 Reputation points Microsoft Employee
    2025-04-15T12:51:18.15+00:00

    For Windows OS (Win10/11, Server 2019/2022/2025), the MDE files/services/reg keys are built into the OS. Manually deleting these files is not recommended and could put your machines into a broken state if/when you ever want to onboard them back to MDE.

    For macOS, you can find more info here: https://learn.microsoft.com/en-us/defender-endpoint/mac-resources#uninstalling

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.