> For the complete documentation index, see [llms.txt](https://docs.easy2patch.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.easy2patch.com/configuring/easy2patch-4.0-settings/deployment-settings/defender.md).

# Defender

<figure><img src="/files/wboCZV0Wkr3yHwAVlnNu" alt=""><figcaption></figcaption></figure>

* **Disable/Enable:** This option enables or disables Easy2Patch's Defender integration.
* **Auto Assignment:** Use this option to allow Easy2Patch to automatically assign updates to azure groups that selected in **Azure Groups** option.
* **Azure Groups:** Select Azure Groups in this combo box to deploy updates.
* **Minimum Score:** Easy2Patch detects updates above the score specified here. Then, it scans through Intune to see if it is installed on the corporate systems. If it finds an installed application, Easy2Patch publishes updates regardless of whether a selection is made on the Update screen or not.
* **Deployment Purpose:** This option controls how Easy2Patch distributes updates. Options include:
  * **Available:** When application deployed to client computer or user, application don't install automatically. Is available to install for user in Company Portal.
  * **Required:** When application deployed to client computer or user, application install automatically. Install for user in Company Portal.

**Publishing Settings**

The publishing settings control how Easy2Patch publishes updates. These settings include:

* **Publish to WSUS:** This option allows Easy2Patch to publish updates to a Windows Server Update Services (WSUS) server.
* **Publish to Intune:** This option allows Easy2Patch to publish updates to Microsoft Intune.

**Publish Options**

* **Overwrite previously published application:** Easy2Patch overwrites older application and change all information with new one. Deployment and other application IDs will not changed.
* **If there is an old version application, retire it and send a new one:** This option allows Easy2Patch to retire an old update version and publish a new one.

{% hint style="success" %}
The **Save** button saves any changes you make to the settings.
{% endhint %}

**Note:** If one or more **Azure Groups** are selected, Easy2Patch scans only the devices that belong to the selected groups.

If no Azure Group is selected, Easy2Patch performs vulnerability scanning across all managed devices in the organization. Therefore, in the current configuration, since no Azure Group is selected, scanning is performed organization-wide.

&#x20;

**Note:** Easy2Patch evaluates only the applications that are identified as vulnerable by Microsoft Defender Vulnerability Management and have a publishable package available in the Easy2Patch catalog. For an application to be published automatically, it must not be excluded on the Defender screen, its highest CVSS score must be equal to or greater than the configured **Minimum Score**, and a publishable package must exist in the catalog. Applications that meet these conditions are published to Microsoft Intune and assigned to the selected Azure group. While the assignment is performed at the group level, the installation is evaluated on a per-device basis. If a device has an older version of the application installed, the update is deployed. If the application is not installed on the device or is already up to date, the device is reported as **Not Applicable**, and no installation is performed.

&#x20;

**Note:** Applications reported as vulnerable by Microsoft Defender Vulnerability Management may not always be deployed to client devices for several reasons. The first step is to verify whether the application has been published to Microsoft Intune. If the application does not exist in Intune, it may not have been published because a Defender mapping is not available in the Easy2Patch catalog, the application's highest CVSS score is below the configured **Minimum Score**, the application has been excluded on the Defender screen, no publishable package exists in the catalog, or the affected device has not reported data to Microsoft Defender for an extended period. If the application has been published to Intune but is not installed on client devices, this is typically the result of the per-device applicability evaluation. Devices where the application is not installed or is already up to date are reported as **Not Applicable**, and no installation is performed. Additionally, if **Deployment Purpose** is configured as **Available**, the application is not installed automatically and must be installed manually by the user through the **Company Portal**. To enable automatic deployment, **Deployment Purpose** should be configured as **Required**.

&#x20;
