If you disable Real Time Protection, does it disable MDE isolation capabilities ?

YATA 0 Reputation points
2025-10-27T17:51:52.5833333+00:00

Hello,

In a scenario where you have Windows Defender as an AV, and Microsoft defender for endpoint as an EDR, and tamper protection is disabled :

If someone disables real time protection (Set-MpPreference -DisableRealTimeMonitoring $True), is it still possible to use MDE capabilities to isolate the device?

I know that MDE relies on other processes such as SenseNDR and MsSense, and it's not possible to disable MDE processes and services even as a SYSTEM but I don't know if there is an impact on the MDE capabilities specially the isolation one.

Thank you.

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.