Edit

Manage tamper protection using tenant attach with Configuration Manager, version 2006

Tamper protection helps protect certain security settings, such as virus and threat protection, from being disabled or changed. If you're part of your organization's security team, and you're using version 2006 of Configuration Manager, you can manage the tamper protection feature for devices by using a method called tenant attach. Tenant attach enables you to sync your on-premises-only Configuration Manager devices into the Intune admin center, and then deliver endpoint security configuration policies to on-premises collections & devices.

Using Configuration Manager with tenant attach, you can turn on (or off) the tamper protection feature for some or all devices.

Important

When tamper protection is turned on, tamper-protected settings can't be changed. To avoid breaking management experiences, including Intune and Configuration Manager, keep in mind that changes to tamper-protected settings might appear to succeed but are actually blocked by tamper protection. Depending on your particular scenario, you have several options available:

  • If you must make changes to a device but find that those changes are getting blocked by tamper protection, use troubleshooting mode to temporarily disable the tamper protection feature on the device.
  • Use Intune or Configuration Manager to exclude devices from tamper protection.

Prerequisites

Make sure your environment meets the following requirements before you configure tamper protection with tenant attach.

Supported operating systems

Tamper protection using tenant attach is supported on the following operating systems:

  • Windows

Turn tamper protection on or off by using tenant attach

First, set up tenant attach. To learn more, see Get started: Create and deploy endpoint security policies from the admin center.

Then, create a new policy. To create a new policy, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the policy, use these settings:

  • Policy type: Antivirus
  • Platform: Windows 10, Windows 11, and Windows Server (ConfigMgr)
  • Profile: Windows Security experience (preview)
  • Configuration settings: Set Enable tamper protection to prevent Microsoft Defender from being disabled to Enabled under Windows Security

Finish selecting options and settings for your policy and deploy the policy to your devices.

Screenshot showing Windows Security settings with tamper protection enabled.

The following resources provide more information about tamper protection: