MD-102 · Question #470
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft…
The correct answer is B. From the Microsoft Intune admin center, create an antivirus policy. To prevent users from disabling Microsoft Defender for Endpoint, you create an Endpoint Security Antivirus policy in the Intune admin center. This policy enables Tamper Protection and enforces Defender settings so that local users cannot turn off real-time protection or modify…
Question
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?
Options
- AFrom the Microsoft Intune admin center, create a security baseline.
- BFrom the Microsoft Intune admin center, create an antivirus policy.
- CFrom the Microsoft Entra admin center, create a Conditional Access policy.
- DFrom the Microsoft Intune admin center, create a device compliance policy.
How the community answered
(19 responses)- A5% (1)
- B63% (12)
- C21% (4)
- D11% (2)
Explanation
To prevent users from disabling Microsoft Defender for Endpoint, you create an Endpoint Security Antivirus policy in the Intune admin center. This policy enables Tamper Protection and enforces Defender settings so that local users cannot turn off real-time protection or modify core Defender configurations. A security baseline (A) can also configure Defender, but an antivirus policy is the most targeted and direct control. A Conditional Access policy (C) controls access decisions, and a device compliance policy (D) evaluates state but does not actively enforce or lock Defender settings.
Topics
Community Discussion
No community discussion yet for this question.