Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community
Tamper protection will be turned on for all enterprise customers
Published Sep 20 2022 05:00 AM 158K Views

Tamper protection in Microsoft Defender for Endpoint protects your organization from unwanted changes to your security settings. Tamper protection helps prevent unauthorized users and malicious actors from turning off threat protection features, such as antivirus protection. Tamper protection also includes the detection of, and response to, tampering attempts.


Starting last year, to better protect our customers from ransomware attacks we turned on tamper protection by default for all new customers with Defender for Endpoint Plan 2 or Microsoft 365 E5 licenses. To further protect our customers, we are announcing that tamper protection will be turned on for all existing customers, unless it has been explicitly turned off in the Microsoft 365 Defender portal. For customers who haven’t already configured tamper protection, they’ll soon receive a notification stating that it will be turned on in 30 days. For example, public preview customers receive a notification on September 21, 2022 indicating that tamper protection will be turned on 30 days later, on October 24, 2022.


The following screenshot shows what the notification looks like:




Why should tamper protection be turned on?

Human operated ransomware is one of the biggest cybersecurity challenges facing customers today.  Post-mortems of ransomware attacks have revealed two things: 

  • Attackers are using a common set of tactics, techniques, and procedures (TTPs)
  • Defender for Endpoint could have helped more in preventing the attack if the controls that address those TTPs were configured. 

We recommend that you turn tamper protection on and keep it enabled across your organization.


How to opt out

If you prefer that tamper protection not be turned on automatically for your tenant, you can explicitly opt out as follows:

  1. Go to and sign in.
  2. Go to Settings > Endpoints > Advanced features
  3. Turn tamper protection on by selecting its toggle.
  4. Select Save preferences
  5. Turn tamper protection off by selecting its toggle.
  6. Select Save preferences.


By explicitly turning tamper protection off, your intent to keep tamper protection turned off will be registered for your tenant. For more information see Protect security settings with tamper protection | Microsoft Docs.


How to disable tamper protection



If you manage a device with You disable tamper protection by


(Microsoft Endpoint Manager)

Creating a Windows Security experience profile in Microsoft Endpoint Manager
Configuration Manager, version 2006 using tenant attach Creating an endpoint security policy

Microsoft 365 Defender portal

or 3rd party MDM

Using Security Management for Defender for Endpoint

Note: Tamper protection is included in the Windows Security Experience, located within the Virus & threat protection settings section.


Learn more


Version history
Last update:
‎Sep 22 2022 02:52 PM
Updated by: