Microsoft's endpoint management product run on-premises, used to roll out software, settings and updates to devices. A server with its client installed is not thereby onboarded to Defender for Cloud.
Also called Configuration Manager.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Configuration Manager in context, with comparison tables and the common traps.
Related terms
- Controlled configuration
In preview, this builds on tamper protection so Antivirus and ASR settings coming from Intune override anything set locally, by Configuration Manager or by Group Policy. You turn it on in the Antivirus profile of the Windows Security experience.
- Managed installer
Software deployed through a nominated distribution tool, Intune or Configuration Manager for instance, is trusted automatically under this App Control for Business feature, tracked via an AppLocker rule collection. Earlier installs are not tagged retrospectively.
- MDT
Microsoft Deployment Toolkit, a now-retired tool for deploying Windows on premises; it receives neither support nor updates. Microsoft's suggested replacements are Windows Autopilot, or OSD in Configuration Manager for organisations that keep on-premises infrastructure.
- OSD
Configuration Manager's way of imaging and rolling out Windows with task sequences, which remains fully supported on-premises.
- Windows Autopilot for existing devices
Brings machines already in use through Autopilot. Configuration Manager reinstalls Windows using a task sequence that includes an Autopilot configuration file.