If you disable Real Time Protection, does it disable MDE isolation capabilities ?
YATA
0
Reputation points
Hello,
In a scenario where you have Windows Defender as an AV, and Microsoft defender for endpoint as an EDR, and tamper protection is disabled :
If someone disables real time protection (Set-MpPreference -DisableRealTimeMonitoring $True), is it still possible to use MDE capabilities to isolate the device?
I know that MDE relies on other processes such as SenseNDR and MsSense, and it's not possible to disable MDE processes and services even as a SYSTEM but I don't know if there is an impact on the MDE capabilities specially the isolation one.
Thank you.
Microsoft Security | Microsoft Defender | Other
Sign in to answer