Share via

Attack Surface Rules - Teams

BmoreOs 141 Reputation points
2022-05-04T19:48:31.817+00:00

I have enabled some ASR rules and a particular Security Mitigation log is posting non stop, every 1 minute. Anyone know what this is or what Teams is trying to do? Should I have any concerns? We haven't noticed any issues but I am worried something might pop up in the future.

198919-image.png

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups
Microsoft Teams | Microsoft Teams for business | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Limitless Technology 40,106 Reputation points
    2022-05-10T07:17:08.3+00:00

    Hi there,

    You don't need to worry about these as Exploit protection automatically applies many exploit mitigation techniques to operating system processes and apps.

    Defender for Endpoint provides detailed reporting into events and blocks as part of its alert investigation scenarios.

    Protect devices from exploits https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/exploit-protection?view=o365-worldwide

    You can also use audit mode to evaluate how to exploit protection would affect your organization if it were enabled.

    When mitigation is found on the device, a notification will be displayed from the Action Center. You can customize the notification with your company details and contact information.

    --------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.