hello,
I have some PCs that get different settings for the same ASR-Rule.
Example:
Directly after boot: 'Block Win32 API calls from Office macro ** Action: Disabled'
After 5 minutes: 'Block Win32 API calls from Office macro ** Action: Block'
i know that we have different sources for ASR-Rules in intune.
I've checked the following:
Endpoint Security / Attack surface reduction
Setting for rule: OFF
Endpoint Security / Security baselines / Microsoft Defender for Endpoint baseline
Setting for rule: Not configured
Devices / Configuration profiles
No Profile-Type Settings catalog with ASR-Rules in use
I've read that there should be an addition place:
https://learn.microsoft.com/en-us/mem/intune/protect/security-baseline-settings-defender-atp?pivots=atp-december-2020#attack-surface-reduction-rules
"Devices > Configuration policy > Endpoint protection profile > Microsoft Defender Exploit Guard > Attack Surface Reduction"
I cant find this page in tune, may be old ?
Are there more places for configuring ASR-Rules ?
what can i do to determine the source of the rule "Action: Block" für "Block Win32 API-Call" ?
Thanks