Forum Discussion
Implementing ASR - Block credential stealing
- Feb 16, 2024
Yes, this is expected. As a default, ASR policies are supposed to be conservative. There are some malicious activities that behaves in a similar way to legitimate activity. Microsoft defaults on the side of caution and alerts on these files. This is not unusual.
I suggest that you add exceptions for necessary Windows files, so you don't encounter a situation where you block critical processes.
The best practice here would be to review these policies on a scheduled basis. Digital environments can change and policies should be reviewed to ensure they are still relevant.
Yes, this is expected. As a default, ASR policies are supposed to be conservative. There are some malicious activities that behaves in a similar way to legitimate activity. Microsoft defaults on the side of caution and alerts on these files. This is not unusual.
I suggest that you add exceptions for necessary Windows files, so you don't encounter a situation where you block critical processes.
The best practice here would be to review these policies on a scheduled basis. Digital environments can change and policies should be reviewed to ensure they are still relevant.
will be adding exceptions for them..
- G_Wilson3468Feb 16, 2024Iron ContributorAnytime, glad I could help. Could you mark this as the best answer if it fits that description?