nerdexam
Microsoft

MD-102 · Question #505

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defen

The correct answer is C. From the Microsoft Defender portal, enable tamper protection.. To prevent users from disabling Microsoft Defender for Endpoint, tamper protection must be enabled in the Microsoft Defender portal.

Submitted by femi9· Apr 18, 2026Protect devices

Question

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

Options

  • AFrom the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
  • BFrom the Microsoft Intune admin center, create an account protection policy.
  • CFrom the Microsoft Defender portal, enable tamper protection.
  • DFrom the Microsoft Intune admin center, create a device compliance policy.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    13% (4)
  • C
    74% (23)
  • D
    10% (3)

Why each option

To prevent users from disabling Microsoft Defender for Endpoint, tamper protection must be enabled in the Microsoft Defender portal.

AFrom the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.

An attack surface reduction (ASR) policy focuses on preventing specific attack behaviors, not on preventing users from disabling security features directly.

BFrom the Microsoft Intune admin center, create an account protection policy.

An account protection policy enhances identity and credential security but does not specifically prevent users from disabling Microsoft Defender for Endpoint.

CFrom the Microsoft Defender portal, enable tamper protection.Correct

Tamper protection is a specific security feature in Microsoft Defender for Endpoint that prevents unauthorized users or malicious software from disabling or altering core Defender settings, such as real-time protection. Enabling this setting ensures that local users cannot turn off Microsoft Defender for Endpoint features on their Windows 11 devices.

DFrom the Microsoft Intune admin center, create a device compliance policy.

A device compliance policy enforces security standards for devices to access resources but does not directly prevent a user from locally disabling Defender for Endpoint settings; tamper protection is the specific mechanism for this.

Concept tested: Microsoft Defender for Endpoint tamper protection

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection

Topics

#Tamper Protection#Microsoft Defender for Endpoint#Endpoint Protection#Windows 11

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice