Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Built-in protection in Microsoft Defender for Endpoint applies default security settings that help protect Windows and macOS devices from ransomware and other threats. Built-in protection complements next-generation protection and attack surface reduction capabilities that help prevent, detect, investigate, and respond to advanced threats.
Use this article to understand how built-in protection works and find the appropriate method to manage tamper protection settings.
Tip
To strengthen protection for your organization's devices, configure these capabilities:
What is built-in protection, and how does it work?
Built-in protection applies default settings automatically as devices are onboarded to Defender for Endpoint. These settings help protect devices from ransomware and other threats. Built-in protection initially enabled tamper protection for your organization and later expanded to other default settings. For more information, see the Tech Community blog post, Tamper protection will be turned on for all enterprise customers.
Your security team can change the built-in protection settings to meet your organization's needs.
Note
Built-in protection sets default values for Windows and macOS devices. Endpoint security settings configured through baselines or policies in Microsoft Intune override the built-in protection settings.
Can I opt out?
You can opt out of built-in protection by configuring your own security settings. Settings that you configure through a supported management method override the built-in protection defaults. For available configuration methods, see the next section.
Can I change built-in protection settings?
Built-in protection is a set of default settings. Your security team isn't required to keep these default settings in place. To meet your organization's business needs, your security team can change the following security features:
- Cloud protection: Configure cloud protection in Microsoft Defender Antivirus
- Tamper protection
- Attack surface reduction (ASR) rules: Configure attack surface reduction rules and exclusions
- Network protection: Configure network protection in Microsoft Defender Antivirus