Intune Migration: Current State & the Defender / Huntress Split

Intune · Security · Field Notes

Intune Migration: Current State

Where the Intune baseline stands, and how we divide Microsoft Defender responsibility between Intune and Huntress.

By Nick Falzetti  ·  July 22, 2026  ·  5 min read

The Intune environment is no longer in the early design phase - the core baseline foundation is in place. The next phase is validation and operational rollout.

That means confirming application deployments, expanding policies in controlled waves, rebuilding Conditional Access carefully, and adding Autopilot and the Enrollment Status Page once the application baseline is stable.

AddendumHuntress & Microsoft Defender integration

A clear division of responsibility keeps Defender clean: Intune owns the protection settings, Huntress owns exclusions and response.

Intune owns (protection settings)

  • Realtime, Cloud, and Behavior Monitoring protection
  • PUA Protection and Network Protection
  • Signature updates, email scanning, archive scanning
  • Sample submission and the overall Defender security configuration

Huntress owns (exclusions & response)

  • Defender exclusions and Huntress process exclusions
  • EDR monitoring and threat hunting
  • SOC response and managed antivirus recommendations

FindingsHuntress review & exclusions strategy

  • Huntress confirmed that Intune policies take precedence over Huntress-managed Defender settings.
  • The existing settings align closely with Huntress recommendations.
  • Excluded paths, processes, and extensions remain Not Configured in Intune - Huntress is the authority for exclusions.
  • Streamline3 application paths and Huntress agent processes are managed by Huntress and not duplicated in Intune.

Local Admin Merge = Enabled (equivalent to Disable Local Admin Merge = Disabled). This allows Huntress-managed exclusions to merge successfully.

ChangesDefender policy changes

  • Signature update interval: 4 hours → 6 hours.
  • Signature update fallback order: MicrosoftUpdateServer|MMPC → Not Configured (Intune error 65000).

GuidanceFuture administrator guidance

  • Do not create Defender exclusions in Intune unless specifically documented and approved.
  • Maintain Intune as the authority for protection settings and Huntress as the authority for exclusions.