nerdexam
Microsoft

MD-102 · Question #483

You have a Microsoft 365 E5 subscription. You use Microsoft Intune to manage all Windows 11 devices. You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface…

The correct answer is C. Configure ASR Only Per Rule Exclusions in Profile1. To unblock an Adobe Reader plug-in blocked by an Attack Surface Reduction (ASR) policy in Intune, you need to configure ASR exclusions directly within the existing policy.

Submitted by yuki_2020· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 E5 subscription. You use Microsoft Intune to manage all Windows 11 devices. You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile1 to all the devices. A user reports that an Adobe Reader plug-in is now blocked. You need to ensure that the plug-in is unblocked. What should you do?

Options

  • ACreate an Endpoint Privilege Management policy and assign the policy to all the devices.
  • BAdd a scope tag to Profile1.
  • CConfigure ASR Only Per Rule Exclusions in Profile1.
  • DCreate a device compliance policy and assign the policy to all the devices.

How the community answered

(67 responses)
  • A
    7% (5)
  • B
    13% (9)
  • C
    49% (33)
  • D
    30% (20)

Why each option

To unblock an Adobe Reader plug-in blocked by an Attack Surface Reduction (ASR) policy in Intune, you need to configure ASR exclusions directly within the existing policy.

ACreate an Endpoint Privilege Management policy and assign the policy to all the devices.

Endpoint Privilege Management policies manage elevated permissions for standard users, which is not the mechanism to unblock ASR rule blocks.

BAdd a scope tag to Profile1.

Adding a scope tag primarily controls who can manage Profile1 in Intune and does not affect the ASR rules themselves or provide exclusions.

CConfigure ASR Only Per Rule Exclusions in Profile1.Correct

Attack Surface Reduction rules allow for specific file, folder, or process exclusions to prevent legitimate applications from being blocked. Configuring "ASR Only Per Rule Exclusions" within Profile1 will allow the Adobe Reader plug-in to operate without disabling the entire ASR rule.

DCreate a device compliance policy and assign the policy to all the devices.

A device compliance policy defines security baselines for devices but doesn't manage or override specific ASR rule exclusions.

Concept tested: ASR rule exclusions in Intune

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-asr-rules?view=o365-worldwide#exclude-files-and-folders-from-asr-rules

Topics

#Attack Surface Reduction#ASR Exclusions#Intune#Windows 11

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice