Optimize ASR rule deployment and detections
- Microsoft Defender for Endpoint Plan 1
- Microsoft Defender for Endpoint Plan 2
- Microsoft Defender XDR
Want to experience Defender for Endpoint? Sign up for a free trial.
Attack surface management card
The Attack surface management card is an entry point to tools in Microsoft Defender portal that you can use to:
- Understand how ASR rules are currently deployed in your organization.
- Review ASR detections and identify possible incorrect detections.
- Analyze the impact of exclusions and generate the list of file paths to exclude.
Select Go to attack surface management > Reports > Attack surface reduction rules > Add exclusions. From there, you can navigate to other sections of Microsoft Defender portal.
The Add exclusions tab in the Attack surface reduction rules page in Microsoft Defender portal
To access Microsoft Defender portal, you need a Microsoft 365 E3 or E5 license and an account that has certain roles on Microsoft Entra ID. Read about required licenses and permissions.
- Ensure your devices are configured properly
- Get devices onboarded to Microsoft Defender for Endpoint
- Monitor compliance to the Microsoft Defender for Endpoint security baseline
Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.