office application creating child process exclusion ASR

Guillaume AMGAR 6 Reputation points
2023-02-17T09:21:05.2233333+00:00

hi

we activated in block mode after audit the ASR rule "Block all office application from creating child process"

But exclusions does not seems to work (for testing)

1

In deed we work with Factset software that add a plugin in Excel that inject data in Excel but they are all blocked

2023-02-17 10_07_24-Window

2023-02-17 10_07_42-Window

Even excel does not open when launching the Factset plugin

Factset is well know legitimate software its so strange that MS does not have a whitelist but anyway, exclusion are not working at all

thanks for, your help

Microsoft Security | Intune | Security
Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2023-02-18T06:08:34.8166667+00:00

    Try removing the * after factset\ . Check if the exclusions are actually applying on the machine. Get-mpprefence run with admin privileges should get you the list.

    0 comments No comments

  2. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-02-20T01:43:46.0666667+00:00

    @Guillaume AMGAR, Thanks for posting in Q&A.

    Based on my research, it seems the asterisk replaces a single folder. For our situation, I think we can change the value to C:\Program Files (x86)\Factset*.exe. Here is a link with more details for your reference:

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-extension-file-exclusions-microsoft-defender-antivirus?view=o365-worldwide#use-wildcards-in-the-file-name-and-folder-path-or-extension-exclusion-lists

    Meanwhile, I notice per-rule exclusions cannot be added to the existing policy. As it is currently implemented, in order to configure per-rule exclusions, you must create a new policy in MEM to replace the existing policy. Please create a new policy with the new setting value to see if it works:

    User's image

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-deployment-test?view=o365-worldwide#configure-asr-rules-per-rule-exclusions

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.