Microsoft Defender XDR includes device discovery , which can identify unmanaged devices on the same network. When performing on-premises device discovery, only selected onboarded devices act as discovery sensors. To limit which devices perform discovery, you use device groups to scope the discovery sensors. From Microsoft's Defender for Endpoint documentation: "You can limit network discovery to specific onboarded devices by assigning those devices to a device group and enabling discovery only for that group." The other options are incorrect because: * A. Set Discovery mode to Basic - Defines how discovery works, not which devices perform it. * C. Create a tag - Useful for classification, not for discovery scoping. * D. Create an exclusion - Excludes IP ranges or devices from scanning, not the discovery role itself. # Final Answer: B. Create a device group