Forum Discussion
James_Gillies
Oct 08, 2021Brass Contributor
ASR: Block abuse of exploited vulnerable signed drivers
Hey there, I am seeing a recommendation to apply the ASR Rule as listed above. It looks like a fairly new edition to the series of 16 ASR rules that can be configured. However, on closer insp...
- Oct 13, 2021
James_Gillies we have not added this ASR Rule to the MEM ASR rule configuration profile. We have plans to add this configuration option so you don't have to use OMA-URIs so stay tuned.
Thanks,
Jake
mcoombe
Mar 01, 2022Brass Contributor
Jake_Mowrer In our experience neither the OMA-URIs or PowerShell command to enable this ASR rule work when deployed using Intune and Tamper Protection is enabled in MSDE. All although ASR rules have been applied successfully using the MEM ASR rule configuration profile.
mcoombe
Mar 01, 2022Brass Contributor
That should have said "All other ASR rules have been applied successfully using the MEM ASR rule configuration profile."