MD-102 · Question #505
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defen
The correct answer is C. From the Microsoft Defender portal, enable tamper protection.. To prevent users from disabling Microsoft Defender for Endpoint, tamper protection must be enabled in the Microsoft Defender portal.
Question
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?
Options
- AFrom the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
- BFrom the Microsoft Intune admin center, create an account protection policy.
- CFrom the Microsoft Defender portal, enable tamper protection.
- DFrom the Microsoft Intune admin center, create a device compliance policy.
How the community answered
(31 responses)- A3% (1)
- B13% (4)
- C74% (23)
- D10% (3)
Why each option
To prevent users from disabling Microsoft Defender for Endpoint, tamper protection must be enabled in the Microsoft Defender portal.
An attack surface reduction (ASR) policy focuses on preventing specific attack behaviors, not on preventing users from disabling security features directly.
An account protection policy enhances identity and credential security but does not specifically prevent users from disabling Microsoft Defender for Endpoint.
Tamper protection is a specific security feature in Microsoft Defender for Endpoint that prevents unauthorized users or malicious software from disabling or altering core Defender settings, such as real-time protection. Enabling this setting ensures that local users cannot turn off Microsoft Defender for Endpoint features on their Windows 11 devices.
A device compliance policy enforces security standards for devices to access resources but does not directly prevent a user from locally disabling Defender for Endpoint settings; tamper protection is the specific mechanism for this.
Concept tested: Microsoft Defender for Endpoint tamper protection
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection
Topics
Community Discussion
No community discussion yet for this question.