Namespace: microsoft.graph
Note: The Microsoft Graph API for Intune requires an active Intune license for the tenant.
Create a new windowsDefenderAdvancedThreatProtectionConfiguration object.
This API is available in the following national cloud deployments.
Global service |
US Government L4 |
US Government L5 (DOD) |
China operated by 21Vianet |
✅ |
✅ |
✅ |
✅ |
Permissions
One of the following permissions is required to call this API. To learn more, including how to choose permissions, see Permissions.
Permission type |
Permissions (from least to most privileged) |
Delegated (work or school account) |
DeviceManagementConfiguration.ReadWrite.All |
Delegated (personal Microsoft account) |
Not supported. |
Application |
DeviceManagementConfiguration.ReadWrite.All |
HTTP Request
POST /deviceManagement/deviceConfigurations
Request body
In the request body, supply a JSON representation for the windowsDefenderAdvancedThreatProtectionConfiguration object.
The following table shows the properties that are required when you create the windowsDefenderAdvancedThreatProtectionConfiguration.
Property |
Type |
Description |
id |
String |
Key of the entity. Inherited from deviceConfiguration |
lastModifiedDateTime |
DateTimeOffset |
DateTime the object was last modified. Inherited from deviceConfiguration |
createdDateTime |
DateTimeOffset |
DateTime the object was created. Inherited from deviceConfiguration |
description |
String |
Admin provided description of the Device Configuration. Inherited from deviceConfiguration |
displayName |
String |
Admin provided name of the device configuration. Inherited from deviceConfiguration |
version |
Int32 |
Version of the device configuration. Inherited from deviceConfiguration |
allowSampleSharing |
Boolean |
Windows Defender AdvancedThreatProtection "Allow Sample Sharing" Rule |
enableExpeditedTelemetryReporting |
Boolean |
Expedite Windows Defender Advanced Threat Protection telemetry reporting frequency. |
Response
If successful, this method returns a 201 Created
response code and a windowsDefenderAdvancedThreatProtectionConfiguration object in the response body.
Example
Request
Here is an example of the request.
POST https://graph.microsoft.com/v1.0/deviceManagement/deviceConfigurations
Content-type: application/json
Content-length: 267
{
"@odata.type": "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration",
"description": "Description value",
"displayName": "Display Name value",
"version": 7,
"allowSampleSharing": true,
"enableExpeditedTelemetryReporting": true
}
// Code snippets are only available for the latest version. Current version is 5.x
// Dependencies
using Microsoft.Graph.Models;
var requestBody = new WindowsDefenderAdvancedThreatProtectionConfiguration
{
OdataType = "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration",
Description = "Description value",
DisplayName = "Display Name value",
Version = 7,
AllowSampleSharing = true,
EnableExpeditedTelemetryReporting = true,
};
// To initialize your graphClient, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=csharp
var result = await graphClient.DeviceManagement.DeviceConfigurations.PostAsync(requestBody);
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
mgc device-management device-configurations create --body '{\
"@odata.type": "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration",\
"description": "Description value",\
"displayName": "Display Name value",\
"version": 7,\
"allowSampleSharing": true,\
"enableExpeditedTelemetryReporting": true\
}\
'
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
// Code snippets are only available for the latest major version. Current major version is $v1.*
// Dependencies
import (
"context"
msgraphsdk "github.com/microsoftgraph/msgraph-sdk-go"
graphmodels "github.com/microsoftgraph/msgraph-sdk-go/models"
//other-imports
)
requestBody := graphmodels.NewDeviceConfiguration()
description := "Description value"
requestBody.SetDescription(&description)
displayName := "Display Name value"
requestBody.SetDisplayName(&displayName)
version := int32(7)
requestBody.SetVersion(&version)
allowSampleSharing := true
requestBody.SetAllowSampleSharing(&allowSampleSharing)
enableExpeditedTelemetryReporting := true
requestBody.SetEnableExpeditedTelemetryReporting(&enableExpeditedTelemetryReporting)
// To initialize your graphClient, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=go
deviceConfigurations, err := graphClient.DeviceManagement().DeviceConfigurations().Post(context.Background(), requestBody, nil)
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
// Code snippets are only available for the latest version. Current version is 6.x
GraphServiceClient graphClient = new GraphServiceClient(requestAdapter);
WindowsDefenderAdvancedThreatProtectionConfiguration deviceConfiguration = new WindowsDefenderAdvancedThreatProtectionConfiguration();
deviceConfiguration.setOdataType("#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration");
deviceConfiguration.setDescription("Description value");
deviceConfiguration.setDisplayName("Display Name value");
deviceConfiguration.setVersion(7);
deviceConfiguration.setAllowSampleSharing(true);
deviceConfiguration.setEnableExpeditedTelemetryReporting(true);
DeviceConfiguration result = graphClient.deviceManagement().deviceConfigurations().post(deviceConfiguration);
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
const options = {
authProvider,
};
const client = Client.init(options);
const deviceConfiguration = {
'@odata.type': '#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration',
description: 'Description value',
displayName: 'Display Name value',
version: 7,
allowSampleSharing: true,
enableExpeditedTelemetryReporting: true
};
await client.api('/deviceManagement/deviceConfigurations')
.post(deviceConfiguration);
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
<?php
use Microsoft\Graph\GraphServiceClient;
use Microsoft\Graph\Generated\Models\WindowsDefenderAdvancedThreatProtectionConfiguration;
$graphServiceClient = new GraphServiceClient($tokenRequestContext, $scopes);
$requestBody = new WindowsDefenderAdvancedThreatProtectionConfiguration();
$requestBody->setOdataType('#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration');
$requestBody->setDescription('Description value');
$requestBody->setDisplayName('Display Name value');
$requestBody->setVersion(7);
$requestBody->setAllowSampleSharing(true);
$requestBody->setEnableExpeditedTelemetryReporting(true);
$result = $graphServiceClient->deviceManagement()->deviceConfigurations()->post($requestBody)->wait();
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
Import-Module Microsoft.Graph.DeviceManagement
$params = @{
"@odata.type" = "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration"
description = "Description value"
displayName = "Display Name value"
version = 7
allowSampleSharing = $true
enableExpeditedTelemetryReporting = $true
}
New-MgDeviceManagementDeviceConfiguration -BodyParameter $params
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
# Code snippets are only available for the latest version. Current version is 1.x
from msgraph import GraphServiceClient
from msgraph.generated.models.windows_defender_advanced_threat_protection_configuration import WindowsDefenderAdvancedThreatProtectionConfiguration
# To initialize your graph_client, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=python
request_body = WindowsDefenderAdvancedThreatProtectionConfiguration(
odata_type = "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration",
description = "Description value",
display_name = "Display Name value",
version = 7,
allow_sample_sharing = True,
enable_expedited_telemetry_reporting = True,
)
result = await graph_client.device_management.device_configurations.post(request_body)
For details about how to add the SDK to your project and create an authProvider instance, see the SDK documentation.
Response
Here is an example of the response. Note: The response object shown here may be truncated for brevity. All of the properties will be returned from an actual call.
HTTP/1.1 201 Created
Content-Type: application/json
Content-Length: 439
{
"@odata.type": "#microsoft.graph.windowsDefenderAdvancedThreatProtectionConfiguration",
"id": "294373aa-73aa-2943-aa73-4329aa734329",
"lastModifiedDateTime": "2017-01-01T00:00:35.1329464-08:00",
"createdDateTime": "2017-01-01T00:02:43.5775965-08:00",
"description": "Description value",
"displayName": "Display Name value",
"version": 7,
"allowSampleSharing": true,
"enableExpeditedTelemetryReporting": true
}