nerdexam
Microsoft

MD-102 · Question #448

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender…

The correct answer is B. From the Microsoft 365 Defender portal, enable tamper protection. To prevent users from disabling Microsoft Defender for Endpoint on Windows 11 computers, you must enable tamper protection from the Microsoft 365 Defender portal.

Submitted by daniela_cl· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender Antivirus on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

Options

  • AFrom the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
  • BFrom the Microsoft 365 Defender portal, enable tamper protection.
  • CFrom the Microsoft Intune admin center, create an account protection policy.
  • DFrom the Microsoft Entra admin center, create a Conditional Access policy.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    83% (43)
  • C
    4% (2)
  • D
    12% (6)

Why each option

To prevent users from disabling Microsoft Defender for Endpoint on Windows 11 computers, you must enable tamper protection from the Microsoft 365 Defender portal.

AFrom the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.

Attack surface reduction (ASR) policies aim to prevent specific attack behaviors on devices, but they do not directly prevent users from disabling Microsoft Defender services.

BFrom the Microsoft 365 Defender portal, enable tamper protection.Correct

Tamper protection is a specific feature within Microsoft Defender for Endpoint designed to prevent users and malware from disabling or altering critical security features, including real-time protection settings.

CFrom the Microsoft Intune admin center, create an account protection policy.

An account protection policy in Intune is used to configure settings related to user identity and credential protection, such as Windows Hello for Business, not to prevent tampering with antivirus services.

DFrom the Microsoft Entra admin center, create a Conditional Access policy.

A Conditional Access policy in Microsoft Entra ID controls access to cloud apps based on various conditions, but it does not manage endpoint security settings like the ability to disable Microsoft Defender.

Concept tested: Microsoft Defender for Endpoint Tamper Protection

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-tampering-with-defender-security-features?view=o365-worldwide

Topics

#Tamper protection#Defender for Endpoint#Endpoint security#Device protection

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice