How to find sources of ASR conflicts in Intune

magica 20 Reputation points
2023-05-22T06:32:21.07+00:00

hello,

I have some PCs that get different settings for the same ASR-Rule.

Example:

Directly after boot: 'Block Win32 API calls from Office macro ** Action: Disabled'
After 5 minutes: 'Block Win32 API calls from Office macro ** Action: Block'

i know that we have different sources for ASR-Rules in intune.

I've checked the following:

Endpoint Security / Attack surface reduction
Setting for rule: OFF

Endpoint Security / Security baselines / Microsoft Defender for Endpoint baseline
Setting for rule: Not configured

Devices / Configuration profiles
No Profile-Type Settings catalog with ASR-Rules in use

I've read that there should be an addition place:

https://learn.microsoft.com/en-us/mem/intune/protect/security-baseline-settings-defender-atp?pivots=atp-december-2020#attack-surface-reduction-rules

"Devices > Configuration policy > Endpoint protection profile > Microsoft Defender Exploit Guard > Attack Surface Reduction"

I cant find this page in tune, may be old ?

Are there more places for configuring ASR-Rules ?

what can i do to determine the source of the rule "Action: Block" für "Block Win32 API-Call" ?

Thanks

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,720 questions
0 comments No comments
{count} votes

Accepted answer
  1. Bastian Hoffmann 75 Reputation points
    2023-05-22T07:59:08.79+00:00

    I've found anotherer location for the ASR Rules:

    Endpoint Security (Intune Admin Center) / Endpoint Security / Security baselines / Security Baseline for Windows 10 add later

    in this case the category name is "Microsoft Dender" (not Attack Surface Reduction)
    Same rules, different category names..... :-(

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. magica 20 Reputation points
    2023-05-22T07:53:55.3466667+00:00

    i want to update my question not able to accept my own answer... :-(

    0 comments No comments