Share via

Microsoft Defender For Endpoint Lic MS Intune is required to use the Attack surface reduction feature ?

Techit Sriwichai 185 Reputation points
2023-03-19T13:02:41.94+00:00

My company is using Join ADDS On-Prime not using Azure AD Join but I want to adjust Config Attack surface reduction but I don't have Lic Intune what should I do please guide me

Windows for business | Windows Client for IT Pros | Devices and deployment | Set up, install, or upgrade
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Intune | Security
0 comments No comments

Answer accepted by question author

Andrew Blumhardt 10,071 Reputation points Microsoft Employee
2023-03-20T01:35:26.11+00:00

I think it may be possible to configure ASR rules using GPO without Intune. Though it can be difficult to manage without data collection. Usually you would audit and review the results to create exceptions before blocking. Intune and MDE help to gather and manage these better.

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-attack-surface-reduction

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.