<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Defender for Endpoint Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bg-p/MicrosoftDefenderATPBlog</link>
    <description>Microsoft Defender for Endpoint Blog articles</description>
    <pubDate>Tue, 16 Jun 2026 22:58:00 GMT</pubDate>
    <dc:creator>MicrosoftDefenderATPBlog</dc:creator>
    <dc:date>2026-06-16T22:58:00Z</dc:date>
    <item>
      <title>Reduce unnecessary internet exposure with Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/reduce-unnecessary-internet-exposure-with-microsoft-defender/ba-p/4525654</link>
      <description>&lt;P&gt;In today’s threat landscape, &lt;STRONG&gt;internet exposure&lt;/STRONG&gt;, i.e. devices that allow inbound connectivity from the public internet, continues to be a major vector for initial access and compromise. Devices that are exposed to the public internet can significantly increase an organization’s attack surface, making them prime targets for initial access, exploitation, and lateral movement.&lt;/P&gt;
&lt;P&gt;However, not all internet-facing devices represent a security issue. Many are intentionally exposed to support business-critical scenarios such as hosting web applications, enabling remote access, or supporting communication services. The challenge for security teams is not just detecting internet-facing devices, but understanding why a device is exposed, whether that exposure is expected, and what action should be taken. That’s why we’re introducing a&amp;nbsp;&lt;STRONG&gt;new security recommendation in Microsoft Defender that helps organizations&lt;/STRONG&gt; &lt;STRONG&gt;identify, review, and reduce unnecessary internet exposure across their environment.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Understand your internet-facing exposure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;This recommendation focuses specifically on devices that are &lt;STRONG&gt;accessible from the public internet&lt;/STRONG&gt;, meaning they can receive &lt;STRONG&gt;inbound connections initiated from external sources, &lt;/STRONG&gt;not devices that only use the internet for outbound communication.&lt;/P&gt;
&lt;P&gt;Externally reachable assets are often the first point of entry for attackers, making this a critical signal for security prioritization.&lt;/P&gt;
&lt;P&gt;Microsoft Defender identifies internet-facing devices based on signals that indicate &lt;STRONG&gt;external inbound reachability&lt;/STRONG&gt;, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;External scan telemetry identifying devices reachable from the public internet&lt;/LI&gt;
&lt;LI&gt;Network telemetry showing inbound connections from external sources&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By correlating these signals, Defender surfaces devices that are externally reachable.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Introducing internet-facing exposure assessment&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A new recommendation in Microsoft Defender provides a centralized view of devices that are externally reachable from the public internet, helping you understand and manage exposure across your environment.&lt;/P&gt;
&lt;P&gt;This assessment categorizes devices based on their exposure state:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exposed devices: Devices that are reachable from the public internet and require review&lt;/LI&gt;
&lt;LI&gt;Compliant devices: Devices that are not externally reachable, or where the internet exposure has been explicitly validated and accepted by the organization’s security team as intended&lt;/LI&gt;
&lt;LI&gt;Not applicable devices: Devices that do not exhibit inbound internet exposure&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;From the recommendation view, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Drill down into exposed devices and understand why they are reachable&lt;/LI&gt;
&lt;LI&gt;Review context such as exposed services and connectivity&lt;/LI&gt;
&lt;LI&gt;Explore device-level details to support investigation&lt;/LI&gt;
&lt;LI&gt;Track exposure posture across your environment over time&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Take action on your internet exposure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;To access this recommendation in the Defender portal, navigate to &lt;STRONG&gt;Exposure management → Recommendations → Devices → Misconfigurations&lt;/STRONG&gt;. Once Defender identifies internet-facing devices, it provides the context needed to review and take action.&lt;/P&gt;
&lt;H5&gt;Your action plan&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;1. Assess your exposure&lt;/STRONG&gt;&lt;BR /&gt;Review the recommendation to understand which devices in your environment are externally reachable from the public internet and why they were classified as internet-facing.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;2. Validate whether exposure is required&lt;/STRONG&gt;&lt;BR /&gt;Determine if the inbound connectivity is expected for each device. Confirm business need and ownership before taking action.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;3. Prioritize high-risk assets&lt;/STRONG&gt;&lt;BR /&gt;Focus on critical servers or sensitive environments that are exposed to the internet, as they present the highest risk for initial access.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;4. Reduce unnecessary exposure&lt;/STRONG&gt;&lt;BR /&gt;Restrict or remove inbound connectivity where it is not required by closing exposed ports, removing public access, or moving services behind controlled access layers.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;5. Track and maintain posture over time&lt;/STRONG&gt;&lt;BR /&gt;Continuously monitor internet-facing devices to ensure unnecessary exposure is reduced and new exposure is validated as environments evolve.&lt;/P&gt;
&lt;H5&gt;FAQ&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;1. Which devices are currently supported?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation applies to supported Windows client and Windows Server devices. Supported versions include Windows 10, version 1607 and earlier; Windows 10, version 1809 and later; and Windows 11.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Why might there be differences between this recommendation and the Internet-facing filter in device inventory?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation reflects devices observed as internet-facing during the recommendation assessment window. Device exposure can change over time, and different Microsoft Defender experiences may refresh at different times.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;As a result, temporary differences may occur between this recommendation and the Internet-facing filter in device inventory.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;For the most current device-level view, use the Internet-facing filter in device inventory. If a device was recently remediated or its exposure recently changed, allow time for the recommendation status to refresh.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. Could regular employee laptops or personal devices appear as internet-facing?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This recommendation evaluates supported devices onboarded to Microsoft Defender for Endpoint and focuses specifically on inbound internet reachability.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Typical internet usage, such as web browsing, generates outbound traffic and does not by itself classify a device as internet-facing.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Devices are identified as internet-facing only when they are externally reachable from the public internet.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;As a result:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;UL&gt;
&lt;LI&gt;Personal devices that are not onboarded to Microsoft Defender for Endpoint are not included in this assessment.&lt;/LI&gt;
&lt;LI&gt;Corporate laptops may appear as internet-facing if they are directly reachable from the internet, which may indicate an unintended network exposure or configuration issue.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;For additional guidance on investigating and managing internet-facing devices, see:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Learn how Defender identifies and maps externally reachable devices across your environment &lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/discovering-internet-facing-devices-using-microsoft-defender-for-endpoint/3778975" target="_blank" rel="noopener"&gt;Discovering internet-facing devices using Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn how to review and investigate internet-facing device exposure &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/investigate-machines" target="_blank" rel="noopener"&gt;Investigate devices in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn more about&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-microsoft-secure-score-devices?tabs=preview-customers" target="_blank" rel="noopener"&gt;Microsoft Secure Score for Devices in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt;&amp;nbsp;Bookmark the&amp;nbsp;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt;&amp;nbsp;to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;)&amp;nbsp;for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 11 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/reduce-unnecessary-internet-exposure-with-microsoft-defender/ba-p/4525654</guid>
      <dc:creator>hadarshindler</dc:creator>
      <dc:date>2026-06-11T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Introducing scheduled antivirus scans on Microsoft Defender Linux</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-scheduled-antivirus-scans-on-microsoft-defender/ba-p/4524578</link>
      <description>&lt;P&gt;Security teams rely on scheduled scans to ensure consistent coverage across devices, detect dormant or missed threats, and meet compliance requirements. However, managing scans on Linux has traditionally required custom scripts and cron-based setups, which can be hard to scale and maintain. That’s why we’re excited to introduce &lt;STRONG&gt;centrally managed scheduled antivirus scans for Linux in Microsoft Defender&lt;/STRONG&gt;, now available in &lt;STRONG&gt;public preview&lt;/STRONG&gt;. With this release, we are bringing built-in, flexible scheduling capabilities directly into Defender - making it easier to manage and standardize scan behaviour across Linux environments.&lt;/P&gt;
&lt;H4&gt;What’s new&lt;/H4&gt;
&lt;P&gt;With this capability, customers can now configure scheduled antivirus scans on Linux using &lt;STRONG&gt;security settings management policies in the Microsoft Defender portal&lt;/STRONG&gt; for centralized policy enforcement or &lt;STRONG&gt;local Managed JSON configuration&lt;/STRONG&gt; that can be deployed via configuration management tools like ansible, puppet and chef.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The feature supports a flexible set of scheduling options, including &lt;STRONG&gt;hourly quick scans&lt;/STRONG&gt; (interval-based scheduling), &lt;STRONG&gt;daily quick scans&lt;/STRONG&gt; at a defined time, and &lt;STRONG&gt;weekly scans&lt;/STRONG&gt; with configurable scan type (quick or full). In addition, customers can control how scans run with advanced options such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Running scans only when the device is idle&lt;/LI&gt;
&lt;LI&gt;Reducing CPU impact using low CPU priority&lt;/LI&gt;
&lt;LI&gt;Checking for definition updates before scanning&lt;/LI&gt;
&lt;LI&gt;Randomizing scans start times&lt;/LI&gt;
&lt;LI&gt;Ignoring exclusions during scheduled scans&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These capabilities allow security teams to balance &lt;STRONG&gt;coverage, performance, and operational needs&lt;/STRONG&gt; across large Linux environments.&lt;/P&gt;
&lt;H4&gt;Why this matters&lt;/H4&gt;
&lt;P&gt;From a security perspective, scheduled scans play a critical role in detecting &lt;STRONG&gt;dormant threats, missed detections, and malicious artifacts&lt;/STRONG&gt; that may not be caught through real-time protection alone. Without consistent and centrally enforced scheduling, these gaps can increase risk across the environment.&lt;/P&gt;
&lt;P&gt;With this release, scheduled scans are now:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Centrally managed&lt;/STRONG&gt; through Defender policies&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Consistently enforced&lt;/STRONG&gt; across devices&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Aligned with security best practices&lt;/STRONG&gt; for regular scanning&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Integrated into the broader Defender security posture&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This helps organizations strengthen their overall security posture while reducing operational complexity.&lt;/P&gt;
&lt;H4&gt;Get started&lt;/H4&gt;
&lt;P&gt;To get started, ensure devices are running &lt;STRONG&gt;agent version 101.26032.0000 or later (production ring)&lt;/STRONG&gt;, and configure scheduled scans using managed JSON or Defender portal policies.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Learn more about how to &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/schedule-antivirus-scans-linux" target="_blank" rel="noopener"&gt;schedule antivirus scans on Linux&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 10 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-scheduled-antivirus-scans-on-microsoft-defender/ba-p/4524578</guid>
      <dc:creator>Rutuja_dange</dc:creator>
      <dc:date>2026-06-10T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Elevate your telemetry using custom data collection in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</link>
      <description>&lt;P&gt;At Ignite in November, we announced that Microsoft Defender is now the only endpoint protection solution that allows data-hungry security teams to meet specific telemetry needs by optimizing their data collection right within the Defender portal, without the need to rely on fragmented and siloed solutions. Since then, we've heard from customers that this tool has been a game changer, enabling them to hunt through new data types as well as richer data on events already reported. The release of custom data collection was a key milestone in our ongoing journey to make Defender easy to manage and customize.&lt;/P&gt;
&lt;P&gt;Security teams have been asking for guidance and examples of how to get the most out of the tool, so today we're sharing how some organizations can use custom data collection and dynamic tagging to detect command and control (C2) communications, giving defenders elevated visibility and deeper telemetry into attacker activity across the environment.&lt;/P&gt;
&lt;H4&gt;See the data you want to see&lt;/H4&gt;
&lt;P&gt;Defender's default telemetry is tuned to balance performance and signal-to-noise across millions of devices, so it focuses on the events most useful for high-fidelity detection at fleet scale, but many organizations want richer, more granular signals for deeper hunting, compliance, or auditing purposes. Custom data collection lets you go beyond what Defender already captures without ever leaving the Defender portal. Easily build custom collection rules based on your organization’s specific needs using natural language; no PhD required! It includes several highly requested data types, including AMSI for hunting over script content, and Kerberos for hunting auth-based and network attacks.&lt;/P&gt;
&lt;P&gt;This truly integrated custom data offering is possible thanks to Microsoft’s platform approach, as the additional telemetry can be collected and analyzed via Defender and stored via Microsoft Sentinel. It puts you in complete control of any customized, add-on data, including exactly which data types are collected and how long they are stored. No other security solution has fully integrated and customizable telemetry collection and analysis.&lt;/P&gt;
&lt;H4&gt;Example custom telemetry scenario: detecting C2 communications&lt;/H4&gt;
&lt;P&gt;Many organizations have a set of assets that require special attention, like internet-facing servers, domain controllers, and other high-value endpoints where deeper telemetry can make the difference between catching an intrusion early and discovering it after the damage is done.&lt;/P&gt;
&lt;P&gt;Imagine your organization has received threat intelligence on attacks using stealthy C2 frameworks: HTTPS beacons with jittered intervals, DNS-based data exchange, and persistence via scheduled tasks and registry modifications. You want richer visibility into those internet-facing servers and high-value endpoints so you can hunt for these patterns proactively, instead of reconstructing them after the fact.&lt;/P&gt;
&lt;P&gt;Dynamic tags scope these high-value devices into a targeted group, and custom data collection captures the extra process, network, and registry events from them, giving analysts the telemetry they need to hunt for beaconing, suspicious DNS patterns, and persistence before attackers establish a foothold.&lt;/P&gt;
&lt;P&gt;To detect C2 communications using dynamic tagging, follow these steps:&lt;/P&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 1: Tag your devices&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Custom Data Collection rules are scoped to&amp;nbsp;&lt;STRONG&gt;dynamic tags; &lt;/STRONG&gt;once set,&lt;STRONG&gt; &lt;/STRONG&gt;those tags are automatically applied and removed based on conditions you define. Configure them in&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Microsoft Defender XDR &amp;gt; Asset Rule Management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag to apply&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Internet-facing servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InternetFacing-Servers&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Internet facing = true AND OS platform equals&amp;nbsp;Windows Server 2022&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Devices under active investigation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Investigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Manual tag equals&amp;nbsp;UnderInvestigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Bringing manual tags into the dynamic model&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Custom data collection is built around&amp;nbsp;&lt;STRONG&gt;dynamic tags&lt;/STRONG&gt;&amp;nbsp;by design: one leading, unified tagging experience that's more flexible and customizable. Dynamic tags can be driven by device properties, group membership, OS,&amp;nbsp;&lt;EM&gt;or&lt;/EM&gt;&amp;nbsp;by existing manual tags, so anything your team already tags manually flows naturally into custom data collection through a simple Asset Rule Management rule, exactly as Tag 2 above does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this example, analysts manually tag a device&amp;nbsp;UnderInvestigation&amp;nbsp;during incident response. The dynamic rule picks up that manual tag and applies&amp;nbsp;HighSev-Verbose, which custom data collection rules can target. The analyst doesn't need to know about dynamic tags they tag the device the way they always have, and custom data collection activates &lt;STRONG&gt;automatically&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 2: Build your collection rules&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Endpoints &amp;gt; Rules &amp;gt; Custom Data Collection&lt;/STRONG&gt;. Select your Microsoft Sentinel workspace in the top-right corner.&lt;/P&gt;
&lt;P&gt;Before creating rules, confirm you meet every prerequisite in the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;custom data collection documentation&lt;/A&gt;&amp;nbsp;, in particular, your tenant must be onboarded to the&amp;nbsp;&lt;STRONG&gt;Unified Security Operations Platform (USOP)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 1: Outbound network connections from high-risk processes&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Capture connections from processes commonly abused by C2 frameworks living-off-the-land binaries and scripting engines.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-OutboundConnections&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InitiatingProcessFileName Equals: powershell.exe,&amp;nbsp;rundll32.exe,&amp;nbsp;regsvr32.exe,&amp;nbsp;mshta.exe,&amp;nbsp;certutil.exe,&amp;nbsp;msiexec.exe&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 2: DNS query activity&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Many C2 frameworks use DNS for beaconing or data exchange. Default telemetry captures limited DNS data. This rule collects all DNS queries from monitored devices.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-DNSActivity&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;RemotePort equals&amp;nbsp;53&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 3: Persistence mechanisms&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;C2 implants establish persistence via scheduled tasks, registry run keys, or services. Capture process creation events for common persistence tools.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Persistence&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;FileName in (schtasks.exe,&amp;nbsp;reg.exe,&amp;nbsp;sc.exe,&amp;nbsp;at.exe)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 4: Full process and script telemetry during investigations&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;When a device gets the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag, collect everything.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-AllProcesses&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all process creation events)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomScriptEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Script execution&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all script events) – add a condition which is always true such as&lt;/P&gt;
&lt;P&gt;FileName not equals “”&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Collection profiles summary&lt;/STRONG&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rules active&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What gets collected&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Use case&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;C2-Watch&amp;nbsp;list&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;OutboundConnections, DNSActivity, Persistence&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Network connections from, DNS queries, persistence tool usage, DLL sideloading&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Persistent C2 monitoring&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;HighSev-Verbose&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;AllProcesses, ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Every process creation, all script execution&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Full-depth incident response&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&amp;nbsp;when you remove the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag after closing an incident, collection automatically drops back to baseline, no manual rule cleanup needed. This is what makes verbose collection safe to leave configured: it's only active while the tag is.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 3: Hunt&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Rules deploy within 20 minutes to an hour. Query the data in AH directly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detect beaconing patterns processes making regular-interval outbound connections:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Find DNS queries to high-entropy domains (potential DGA):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Spot persistence being established:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Leverage the telemetry from your new collection rule into a Custom Detection so high-value findings raise alerts automatically, instead of waiting for the next manual hunt.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Custom data collection effectively extends your endpoint protection into a targeted, general-purpose log collector, one that's now ready to serve advanced hunting, custom detections,&amp;nbsp;&lt;EM&gt;and&lt;/EM&gt; auditing or regulatory use cases, while default fleet-wide telemetry stays tuned for performance and signal-to-noise. By combining dynamic tagging with purpose-built collection rules, your highest-risk devices are always streaming the signals that matter most, ready for detection and investigation before and during an incident.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;LI&gt;To learn more about custom data collection and how to get started, see our &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</guid>
      <dc:creator>Theo_Cohen</dc:creator>
      <dc:date>2026-06-09T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender now monitors RPC activity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</link>
      <description>&lt;P&gt;Remote procedure call (RPC) is a protocol commonly abused by attackers that allows functions implemented in a separate process, and potentially on a remote machine, to be called as if they were local. Many core Windows and Active Directory capabilities are built on or make use of RPC, which makes it an attractive target. To help protect against remote RPC-based attacks, Microsoft Defender now monitors remote RPC calls, disrupts malicious activity that leverages them, and surfaces relevant telemetry in advanced hunting.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC basics&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;While &lt;A href="https://learn.microsoft.com/en-us/windows/win32/rpc/rpc-start-page" target="_blank" rel="noopener"&gt;RPC is a rich and complicated protocol&lt;/A&gt;, the main components that are relevant for security monitoring purposes are:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Interface&lt;/U&gt;: A logical grouping of functionality exposed by an RPC server. Interfaces are identified by UUID. Example interfaces include Task Scheduler, Remote Registry, and the Service Control Manager, each exposing functionality related to a different Windows OS component.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;OpNum&lt;/U&gt;: Stands for Operation Number, an ordinal that denotes a specific function exposed by an RPC interface. Examples include RCreateServiceW (OpNum 12, Service Control Manager interface) and BaseRegQueryValue (OpNum 17, Remote Registry interface).&lt;/LI&gt;
&lt;/OL&gt;
&lt;H5&gt;&lt;STRONG&gt;Many remote attack techniques and tactics are based on RPC, for example:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Lateral movement&lt;/U&gt;: often abuses RPC functionality for remotely creating tasks, services or invoking WMI.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Credential theft&lt;/U&gt;: DCsync attacks, which abuse privileged compromised accounts to remotely extract credential material from Active Directory, are based on RPC functionality for directory replication. SecretsDump and similar attacks, which remotely extract SAM or LSA secrets, are based on querying a device’s registry remotely, using RPC.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Privilege escalation&lt;/U&gt;: Multiple authentication coercion attacks abuse benign RPC interfaces to coerce servers to authenticate an attacker.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Discovery&lt;/U&gt;: Tools such as SharpHound leverage RPC calls to enumerate users, sessions and shares.&lt;/LI&gt;
&lt;/OL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;For a more comprehensive mapping of RPC interfaces to attack techniques, see&amp;nbsp;&lt;A href="https://github.com/jonny-jhnson/MSRPC-to-ATTACK" target="_blank" rel="noopener"&gt;work&lt;/A&gt; by Jonathan Johnson.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC auditing in Defender&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Since RPC is so heavily used on Windows systems and in Active Directory domains, monitoring remote RPC traffic using network monitors is often expensive and infeasible. Additionally, if the underlying transport protocol is encrypted (such as SMB3), it might be impossible to observe RPC traffic.&lt;/P&gt;
&lt;P&gt;To enable efficient auditing of remote RPC activity regardless of transport-layer protection, Defender research and engineering expanded the existing RPC integration with the Windows Filtering Platform (WFP) to support OpNum-level granularity. This makes it possible to identify and audit the specific RPC function being invoked, rather than only the RPC interface.&lt;/P&gt;
&lt;P&gt;This capability is designed to help detect remote RPC-based attack techniques, where an attacker interacts with RPC interfaces exposed by a target device. For that reason, Defender focuses this monitoring on inbound remote RPC calls observed on the RPC server host. The telemetry is collected using audit-only WFP filters, which do not interfere with normal traffic, while still providing visibility into suspicious remote activity targeting the device. This approach does not require visibility into the source device.&lt;/P&gt;
&lt;P&gt;Local RPC calls, such as inter-process communication on the same device over local transport, and outbound RPC client calls are outside the scope of this monitoring mechanism.&lt;/P&gt;
&lt;P&gt;Using this capability, Defender monitors selected RPC calls, leverages the resulting telemetry to detect malicious activity, and exposes monitored calls in advanced hunting. Defender dynamically monitors selected remote operations from interfaces including, but not limited to: Remote Registry, Service Control Manager, Task Scheduler, and Windows Management Instrumentation (WMI). RPC monitoring for workstations is generally available, while server monitoring is currently in gradual rollout.&lt;/P&gt;
&lt;P&gt;RPC-based detections and disruption triggers are already available in Defender and include detections such as:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Ongoing hands-on-keyboard attack via Impacket toolkit&lt;/LI&gt;
&lt;LI&gt;Suspicious service creation initiated remotely&lt;/LI&gt;
&lt;LI&gt;Indication of local security authority secrets theft&lt;/LI&gt;
&lt;LI&gt;Unusual RPC user and session discovery&lt;/LI&gt;
&lt;LI&gt;Authentication coercion attack&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Example Advanced Hunting queries&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;1. Remote registry key save events, abused for remote credential dumping.&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteRegistryInterface = '338cd001-2244-31f1-aaaa-900038001003'; 
let registrySaveOpnums = dynamic([20, 31]); // BaseRegSaveKey, BaseRegSaveKeyEx 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteRegistryInterface and OpNum in(registrySaveOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Remote Service Creation events, could indicate lateral movement:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteServicesInterface = '367abb81-9844-35f1-ad32-98f038001003'; 
let serviceCreationOpnums = dynamic([12, 24, 44, 45, 60]); // RCreateServiceW, RCreateServiceA, RCreateServiceWOW64A, RCreateServiceWOW64W, RCreateWowService 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteServicesInterface and OpNum in(serviceCreationOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Session discovery events, could indicate account discovery:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let srvsvcInterface = '4b324fc8-1670-01d3-1278-5a47bf6ee188'; 
let netrSessionEnumOpnum = 12; 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == srvsvcInterface and OpNum == netrSessionEnumOpnum 
| summarize dcount(DeviceId) by AccountName, AccountDomain, AccountSid &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the advanced hunting tab to see monitored RPC activity in your environment and stay tuned for more updates from Defender.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:55:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</guid>
      <dc:creator>EdanZwick</dc:creator>
      <dc:date>2026-06-09T16:55:28Z</dc:date>
    </item>
    <item>
      <title>How Microsoft Defender used predictive shielding to proactively disrupt a ransomware attack</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-microsoft-defender-used-predictive-shielding-to-proactively/ba-p/4519498</link>
      <description>&lt;P&gt;Modern ransomware attacks are increasingly designed to blend in with normal IT operations, using trusted administrative tools to quietly weaken defenses and distribute malicious payloads at scale.&lt;/P&gt;
&lt;P&gt;In a recent real‑world incident, a human‑operated ransomware actor attempted to do exactly that by abusing &lt;STRONG&gt;Group Policy Objects (GPOs) to target hundreds of devices, but Microsoft Defender detected the attack and proactively hardened those devices before GPOs were deployed.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;The attacker’s plan&lt;/H4&gt;
&lt;P&gt;The target organization, a large educational institution with more than a couple of thousand devices onboarded to Microsoft Defender, had already experienced a compromise of a domain admin account from an unmanaged device before the ransomware deployment attempt began.&lt;/P&gt;
&lt;P&gt;Because GPOs are a trusted mechanism for pushing configuration changes across devices, they present an attractive path for attackers looking to disable security tools or deploy ransomware broadly without needing to access each machine individually. This attacker’s plan involved weaponizing GPOs to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Push tampering configurations that could disable Defender protections across the environment&lt;/LI&gt;
&lt;LI&gt;Distribute and execute ransomware via scheduled tasks&lt;/LI&gt;
&lt;LI&gt;Leverage built‑in enterprise infrastructure to scale the attack&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This approach allowed the attacker to attempt ransomware deployment through standard administrative channels, minimizing the need for direct interaction with individual devices and increasing the potential for widespread impact.&lt;/P&gt;
&lt;H4&gt;How Defender thwarted the attack&lt;/H4&gt;
&lt;P&gt;First, Defender quickly detected the attack and contained the domain admin account that the attacker had compromised. Then, since the attacker had created a malicious GPO that disabled key Defender protections, a Defender tampering alert was triggered. In response, predictive shielding activated GPO hardening, temporarily pausing the propagation of new GPO policies across all MDE onboarded devices reachable from the attacker’s standpoint and achieved protection of ~85% of devices against the tampering policy before ransomware was deployed.&lt;/P&gt;
&lt;P&gt;Ten minutes later, the attacker attempted to distribute ransomware, but because GPO hardening had already been applied, GPO propagation was already disabled on the targeted devices and the attacker was unsuccessful. Defender recognized that GPO tampering is a precursor to ransomware distribution and acted preemptively. It didn’t wait for ransomware to appear; it acted on what the attacker was&amp;nbsp;&lt;EM&gt;about&lt;/EM&gt; to do, preventing downstream impact such as recovery costs and operational downtime.&lt;/P&gt;
&lt;H4&gt;The results&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Zero machines were encrypted via the GPO path.&lt;/LI&gt;
&lt;LI&gt;Roughly 97% of devices the attacker attempted to encrypt were fully protected by Defender. A limited number of devices&amp;nbsp;experienced encryption during concurrent ransomware activity over SMB; however, attack disruption successfully contained the incident and stopped further impact.&lt;/LI&gt;
&lt;LI&gt;700 devices applied the predictive shielding GPO hardening policy, reflecting the attacker’s broad targeting scope, and blocking the propagation of the malicious policy set by the attacker within approximately 3 hours.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attackers are getting more sophisticated, finding ways to evade detection by abusing legitimate IT tools that organizations rely on and can’t simply turn off. Security teams can’t restrict these mechanisms without impacting daily operations. By detecting ransomware staging and predicting the attacker’s next move, Defender can apply targeted restrictions just in time, shifting from reactive response to proactive prevention, stopping only what matters when it matters while maintaining full business productivity. With average ransom demands now ranging from $2–5M, the downstream recovery and remediation savings from preventing these attacks can be massive.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about this specific attack, check out the full case study: &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/23/case-study-predictive-shielding-defender-stopped-gpo-based-ransomware-before-started/" target="_blank" rel="noopener"&gt;Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started&lt;/A&gt; &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/23/case-study-predictive-shielding-defender-stopped-gpo-based-ransomware-before-started/" target="_blank" rel="noopener"&gt;[microsoft.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 17:16:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-microsoft-defender-used-predictive-shielding-to-proactively/ba-p/4519498</guid>
      <dc:creator>AvivSharon</dc:creator>
      <dc:date>2026-06-01T17:16:47Z</dc:date>
    </item>
    <item>
      <title>Introducing selective response actions for high-value assets in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-selective-response-actions-for-high-value-assets-in/ba-p/4512175</link>
      <description>&lt;P&gt;Deploying Microsoft Defender on high-value assets (HVAs) such as domain controllers, ADFS servers, and other Tier-0 systems, requires a thoughtful approach to balance strong protection with operational stability. Given the powerful response capabilities available, organizations often seek greater control over how these actions are applied in sensitive environments. Many organizations, especially those with strict privileged access management policies, also prefer to limit cloud-initiated administrative actions on Tier-0 systems to align with their security and compliance requirements.&lt;/P&gt;
&lt;P&gt;We introduced simplified onboarding in late 2025 with the release of the Defender deployment tool, and now we’re excited to announce that &lt;STRONG&gt;selective response actions for high-value assets&lt;/STRONG&gt; are now available in public preview to afford security teams greater flexibility within the onboarding process. This new capability provides a more controlled and flexible approach, enabling organizations to define exactly which response actions are allowed on critical assets. Security teams can maintain operational continuity while still benefiting from the full visibility and protection of Defender.&lt;/P&gt;
&lt;H4&gt;How it works&lt;/H4&gt;
&lt;P&gt;Deploying Defender on high-value assets requires additional safeguards. This capability introduces a controlled onboarding experience that enforces strict boundaries from the start.&lt;/P&gt;
&lt;P&gt;Security teams can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Generate a custom onboarding package&lt;/STRONG&gt; tailored specifically for Tier-0 and High-Value Assets&lt;/LI&gt;
&lt;LI&gt;Use the &lt;STRONG&gt;Defender deployment tool&lt;/STRONG&gt;, a lightweight, dynamic tool that simplifies onboarding and removes the need for complex scripts&lt;/LI&gt;
&lt;LI&gt;Leverage &lt;STRONG&gt;secure key validation and package expiry&lt;/STRONG&gt;, ensuring controlled and secure deployment&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Explicitly define which remote response actions are permitted&lt;/STRONG&gt; on sensitive systems&lt;/LI&gt;
&lt;LI&gt;Onboard both &lt;STRONG&gt;Windows workstations and Windows Server environments&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This approach ensures that security controls are applied consistently and cannot be altered post-deployment, reducing the risk of misconfiguration or misuse.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Image 1: selective response actions in the Defender deployment tool&lt;/EM&gt;&lt;EM&gt; package settings&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;Key benefits&lt;/H4&gt;
&lt;P&gt;Selective response actions for high-value assets provide a safer and more controlled way to protect critical systems:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Reduce operational risk&lt;/STRONG&gt; by limiting powerful security actions on Tier-0 assets&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prevent accidental or malicious disruptions&lt;/STRONG&gt; caused by overprivileged or compromised accounts&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Align with privileged access management (PAM) policies&lt;/STRONG&gt; by restricting cloud-initiated administrative actions&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Support compliance and regulatory requirements&lt;/STRONG&gt; with stricter enforcement of security controls&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maintain full Defender visibility and protection&lt;/STRONG&gt; without overexposing sensitive systems&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Provide explicit and granular control&lt;/STRONG&gt; over remote response capabilities&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;&lt;EM&gt;Image 2: view of the available response actions for a particular device in the Defender portal&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;Secure your most critical assets with confidence&lt;/H4&gt;
&lt;P&gt;You can now extend Defender for Endpoint protection to your most critical Windows systems, while maintaining strict control over how those systems are accessed and managed. This capability empowers security teams to protect what matters most with confidence and precision.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Learn more about how to set up &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets" target="_blank" rel="noopener"&gt;selective response actions for high value assets&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 May 2026 15:50:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-selective-response-actions-for-high-value-assets-in/ba-p/4512175</guid>
      <dc:creator>amibarayev</dc:creator>
      <dc:date>2026-05-18T15:50:40Z</dc:date>
    </item>
    <item>
      <title>Assess Secure Boot status with Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/assess-secure-boot-status-with-microsoft-defender/ba-p/4510356</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;Understanding the Secure Boot certificate challenge&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Secure Boot is a foundational security feature that validates the integrity of your device's boot process, ensuring only trusted software can run during system startup. This protection has been quietly defending enterprise devices since 2012, but the original 2011 certificates that enable this trust are approaching their expiration date.&lt;/P&gt;
&lt;P&gt;When certificates expire in June 2026, devices that haven't transitioned to the new Windows UEFI CA 2023 certificates will no longer be able to receive new security protections for the early boot process. While these devices will continue to boot, they may no longer be able to receive or enforce new protections at the earliest stages of system startup. Over time, this can weaken the device’s root of trust and expose it to classes of attacks that operate before the operating system and security controls are fully loaded:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Malicious or tampered boot components may no longer be reliably blocked if they are not signed with trusted certificates&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Devices may be unable to adopt future Secure Boot policy updates designed to mitigate newly discovered boot-level threats&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Attackers may attempt to leverage boot-level persistence techniques that operate below the visibility of traditional security controls&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As new vulnerabilities and protections are introduced, devices that are not updated will gradually fall behind in their ability to enforce trust at boot, but the challenge isn’t just knowing that this transition needs to happen, it’s understanding which devices in your fleet have successfully completed the update and which still require attention.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Introducing Secure Boot 2023 certificate assessment&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A new recommendation in Defender allows you to ensure that devices are updated to Secure Boot 2023 certificates and boot manager, providing a centralized, at-scale view of Secure Boot certificate readiness across your environment.&lt;/P&gt;
&lt;P&gt;This assessment automatically categorizes your devices into:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Exposed devices&lt;/STRONG&gt;: Still trusting older Secure Boot certificates without trust for newer Secure Boot certificates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliant devices&lt;/STRONG&gt;: Successfully relying on the 2023 certificates and signed boot manager&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Not applicable devices&lt;/STRONG&gt;: Systems where Secure Boot is disabled or not supported&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;From the recommendation view, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Drill down into exposed devices and identify exactly which systems require attention&lt;/LI&gt;
&lt;LI&gt;Filter by OS platform and device context to prioritize remediation efforts&lt;/LI&gt;
&lt;LI&gt;Export device data to share with infrastructure and platform teams&lt;/LI&gt;
&lt;LI&gt;Track rollout progress across your organization&lt;/LI&gt;
&lt;LI&gt;Integrate findings into existing security posture workflows&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;[Secure Boot 2023 recommendation in MDE portal showing deployment status across the fleet]&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Take action on your Secure Boot readiness&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;To access this tool in the Defender portal, navigate to Exposure Management → Recommendations → Devices → Misconfigurations. Once Defender identifies exposed devices, it provides remediation guidance.&lt;/P&gt;
&lt;P&gt;For detailed deployment guidance, including enterprise rollout strategies and validation practices, see: &lt;A href="https://aka.ms/GetSecureBoot" target="_blank" rel="noopener"&gt;https://aka.ms/GetSecureBoot&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Your action plan&lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess your exposure&lt;/STRONG&gt;&lt;BR /&gt;Navigate to the tool to understand how many devices in your environment require updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Engage the right teams&lt;/STRONG&gt;&lt;BR /&gt;Secure Boot certificate deployment is typically owned by infrastructure and platform teams, so coordinate across your organization.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prioritize high-value assets&lt;/STRONG&gt;&lt;BR /&gt;Focus remediation efforts on critical devices and sensitive environments first.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Track progress over time&lt;/STRONG&gt;&lt;BR /&gt;Monitor rollout progress and ensure coverage improves ahead of the June 2026 deadline.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Visit the comprehensive Secure Boot guidance at&amp;nbsp;&lt;A href="https://aka.ms/GetSecureBoot" target="_blank" rel="noopener"&gt;https://aka.ms/GetSecureBoot&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn more about&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-microsoft-secure-score-devices?tabs=preview-customers" target="_blank" rel="noopener"&gt;Microsoft Secure Score for Devices in Microsoft Defender for Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 27 Apr 2026 16:38:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/assess-secure-boot-status-with-microsoft-defender/ba-p/4510356</guid>
      <dc:creator>amitcohen</dc:creator>
      <dc:date>2026-04-27T16:38:22Z</dc:date>
    </item>
    <item>
      <title>Introducing effective settings: See security configurations enforced on your device</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-effective-settings-see-security-configurations/ba-p/4499551</link>
      <description>&lt;H4&gt;See exactly which security configurations are enforced on your device&lt;/H4&gt;
&lt;P&gt;Security teams spend significant time defining policies for Microsoft Defender security settings. But when it comes to investigations or troubleshooting, the real question is often simple: &lt;EM&gt;what is currently being enforced on this device?&lt;/EM&gt; Today, we’re excited to share that the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/investigate-machines?wt.mc_id=MVP_452337#configuration-management---effective-settings" target="_blank" rel="noopener"&gt;settings experience&lt;/A&gt; is now generally available in Defender to provide this critical visibility.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure #1: Effective settings tab on the device page&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;From intended policy to real-world enforcement&lt;/H4&gt;
&lt;P&gt;Understanding device security posture sometimes means correlating policy intent across multiple management sources, including Intune, Group Policy Object (GPO), and local admin configurations. With effective settings, administrators can see the &lt;EM&gt;effective value&lt;/EM&gt; of each security setting on a specific device—along with the configuration source—and quickly identify configuration attempts that didn’t take effect. This helps eliminate silent gaps where intended protections are not actually enforced, reducing the risk of unnoticed exposure during incidents or active attacks. And this shift from intent to reality helps teams move faster when validating posture, investigating incidents, or resolving conflicts between management tools.&lt;/P&gt;
&lt;H4&gt;A new view on the device page&lt;/H4&gt;
&lt;P&gt;The effective settings tab is available as a new tab under the &lt;STRONG&gt;configuration management&lt;/STRONG&gt; tab on the device page. From this single location, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;View the &lt;STRONG&gt;actual value&lt;/STRONG&gt; enforced for each security setting&lt;/LI&gt;
&lt;LI&gt;Identify the &lt;STRONG&gt;configuring source&lt;/STRONG&gt; responsible for that value&lt;/LI&gt;
&lt;LI&gt;See &lt;STRONG&gt;additional configuration attempts&lt;/STRONG&gt; from other sources that were evaluated but not applied&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For complex or layered scenarios such as Microsoft Defender Antivirus exclusions and Attack Surface Reduction (ASR) rules, all configured rules are shown together with their effective value, configuring source, and additional configuration attempts&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This makes it far simpler to understand why a device behaves the way it does, without jumping between consoles or guessing which policy “won.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure #2: Simple settings side panel&lt;/EM&gt;&lt;/img&gt;&lt;img&gt;&lt;EM&gt;Figure #3: Complex settings side panel&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;Practical use cases&lt;/H4&gt;
&lt;P&gt;Security admins and analysts can use &lt;STRONG&gt;effective settings&lt;/STRONG&gt; for use cases like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Validating enforcement&lt;/STRONG&gt; – Confirm that intended security configurations are truly applied on devices&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Troubleshooting conflicts&lt;/STRONG&gt; – Quickly spot competing policies or management sources that prevented a configuration from being enforced&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improving operational confidence&lt;/STRONG&gt; – Reduce uncertainty by relying on an authoritative, device-level view of security settings&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Platform support and what’s next&lt;/H4&gt;
&lt;P&gt;The current release focuses on &lt;STRONG&gt;Windows platform antivirus security settings&lt;/STRONG&gt;, including ASR rules and exclusions. This is just the beginning. Our roadmap includes expanding coverage across additional platforms, and a broader set of security settings configured through the Microsoft 365 Defender and Intune portals.&lt;/P&gt;
&lt;H4&gt;Getting started&lt;/H4&gt;
&lt;P&gt;If you’re using Microsoft Defender for Endpoint, head to a device page and open the &lt;STRONG&gt;configuration management → effective settings&lt;/STRONG&gt; tab to explore the experience firsthand.&lt;/P&gt;
&lt;P&gt;Supported versions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Defender for Endpoint Sense client: 10.8735.26018.1000 or later&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender Antivirus platform: 4.18.25010.11 (January 2025 release) or later&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/investigate-machines?wt.mc_id=MVP_452337#configuration-management---effective-settings" target="_blank" rel="noopener"&gt;Learn more about investigating devices in Defender&lt;/A&gt;. To get started, navigate to a device page and open the &lt;STRONG&gt;configuration management → effective settings&lt;/STRONG&gt; tab.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Defender endpoint protection, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 09 Mar 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-effective-settings-see-security-configurations/ba-p/4499551</guid>
      <dc:creator>ArielMichaeli1</dc:creator>
      <dc:date>2026-03-09T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Transparent and customizable onboarding for modern and legacy Windows devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/transparent-and-customizable-onboarding-for-modern-and-legacy/ba-p/4498827</link>
      <description>&lt;P&gt;Onboarding all devices in your estate is paramount for strong security posture. In fact, Microsoft Threat Intelligence research shows that in the majority of ransomware attacks, the spreader machine was a device that was not yet onboarded. But customers often struggle to follow complex steps that differ by OS, accidentally duplicate devices because they can’t tell whether onboarding is in progress or failed, or have incorrect initial configuration settings causing system incompatibility. That’s why we’re introducing an updated onboarding experience via the Defender deployment tool for Windows that improves progress visibility and adds controls—like package naming and configurable expiry—to help administrators manage onboarding securely at scale.&lt;/P&gt;
&lt;H3 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;new&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;The&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;Defender deployment tool streamlines&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;the onboarding process&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;by&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;dynamically adapt&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ing&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;to the operating system, delivering healthy endpoint security to a diverse&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;estate&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;of Windows devices.&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;It&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;is the preferred automated solution&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;that works on&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;modern and legacy devices&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;removes the need for a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;separate onboarding&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;file by embed&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ding the onboarding&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;package and all related information within a downloadable&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;exe&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;that&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;can be run to onboard devices.&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;This &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;updated experience&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;makes&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;onboarding more predictable and transparent, while adding administrative controls that help reduce exposure if onboarding packages are accidentally shared beyond your organization&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;A&amp;nbsp;single, runnable&amp;nbsp;.exe&amp;nbsp;for onboarding&amp;nbsp;with&amp;nbsp;the onboarding information&amp;nbsp;embedded&amp;nbsp;(no separate onboarding file&amp;nbsp;required)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Silent and non-interactive onboarding&amp;nbsp;options&amp;nbsp;to support large-scale deployments with tools like Group Policy or Configuration Manager&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Custom package identifiers&amp;nbsp;to&amp;nbsp;help track and manage onboarding packages across your organization&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Configurable onboarding package expiry (up to one year)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Customizable name identifiers and keys for increased control and visibility&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;New portal entry points and guidance to make it easier to find the right onboarding and offboarding method for Windows, including&amp;nbsp;directly from the device inventory page&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;The new, streamlined onboarding tab in the Defender portal&lt;/img&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;Customize your deployment package&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This experience moves away from using scripts and loose blobs, making it more difficult for onboarding to take place at the hands of unauthorized users and significantly decreasing security issues related to blobs in the wild that don't expire. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;And&amp;nbsp;for the first time, you can set custom expiry&amp;nbsp;dates&amp;nbsp;on onboarding packages&amp;nbsp;for 1 day, 7 days, or a custom amount up to a year.&amp;nbsp;Expiry for onboarding packages protects customers from unwanted onboarding and compliance issues, limiting packages from getting misused if&amp;nbsp;they’re&amp;nbsp;found in a public place. Expiry reduces the likelihood of unauthorized package usage, together with the new portal-provided key that you must input to complete the onboarding process.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Customize your deployment package with a name and expiry date&lt;/img&gt;
&lt;H3&gt;&lt;SPAN data-contrast="none"&gt;See your onboarding telemetry in detail&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Deployment tool events are available in the device timeline and advanced hunting tabs for increased transparency into onboarding progress and errors, so you can quickly address any issues.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;On&amp;nbsp;the new deployment packages page, you can see your organization's onboarding packages&amp;nbsp;at a glance&amp;nbsp;and&amp;nbsp;click to see more package properties, increasing visibility and traceability within the onboarding process. This is&amp;nbsp;a great foundation for adding even more onboarding-related telemetry to view per device in the future. You can even&amp;nbsp;filter by&amp;nbsp;active or expired packages and hide packages you no longer&amp;nbsp;wish&amp;nbsp;to see.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;The new deployment packages page in the Defender portal&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To experience this next iteration of the Defender deployment tool for Windows, navigate to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Settings &amp;gt; Endpoints &amp;gt; Onboarding &amp;gt; Windows&lt;/STRONG&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;or jump there directly from the device inventory page. There you'll see the newly designed onboarding page in the Defender portal, complete with on/offboarding guides. Select the Defender deployment tool from the options shown.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;New onboarding and offboarding buttons on the device inventory page&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;The Defender deployment tool is also available for Linux. We look forward continuing to share ways we're making it easier to onboard devices to Defender.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Learn more&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/defender-deployment-tool-windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Deploy Microsoft Defender endpoint security to Windows devices using the Defender deployment tool (preview) - Microsoft Defender for Endpoint | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/linux-install-with-defender-deployment-tool" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Deploy Microsoft Defender endpoint security to Linux devices using the Defender deployment tool (preview) - Microsoft Defender for Endpoint | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;To learn more about Microsoft Defender's endpoint protection, check out&amp;nbsp;our &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;To learn more about Microsoft Security solutions, visit our&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Bookmark the&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;https://www.microsoft.com/security/blog/&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;https://www.linkedin.com/showcase/microsoft-security/&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;https://twitter.com/@MSFTSecurity&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;)&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 03 Mar 2026 03:25:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/transparent-and-customizable-onboarding-for-modern-and-legacy/ba-p/4498827</guid>
      <dc:creator>Sinclaire_Hamilton</dc:creator>
      <dc:date>2026-03-03T03:25:40Z</dc:date>
    </item>
    <item>
      <title>Introducing library management in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-library-management-in-microsoft-defender/ba-p/4494434</link>
      <description>&lt;P&gt;In dynamic investigation environments, preparation and agility are key. Security analysts working with live response in Microsoft Defender often rely on scripts and tools to triage, investigate, and remediate threats. Until now, these assets had to be uploaded during active sessions, limiting manageability and increasing time to action.&lt;/P&gt;
&lt;P&gt;Recognizing the need for better readiness and control, Defender now introduces a more proactive and efficient way to manage these assets: &lt;STRONG&gt;library management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The new library management experience in Defender brings powerful enhancements to how security teams manage scripts and files used in live response. With this centralized and streamlined interface, analysts no longer need to wait for an active session to organize their investigation tools everything can now be managed proactively, directly from the portal. This enhancement in Defender’s live response tooling improves operational readiness, enhances visibility and control, and helps streamline response workflows across SOC teams.&lt;/P&gt;
&lt;H4&gt;What’s new in library management?&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Centralized script and file management – &lt;/STRONG&gt;Security teams can now upload, manage, and clean up their entire collection of Live Response scripts and files outside of an active investigation. This proactive approach allows better preparation and alignment across analysts.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Upload in advance – &lt;/STRONG&gt;Easily upload PowerShell scripts, batch files, or other response tools ahead of time, so they're immediately accessible when needed during an investigation.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;View script contents in the portal – &lt;/STRONG&gt;No need to switch tools, analysts can review script contents directly within the Defender UI to validate logic and confirm functionality before execution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Clean and organize – &lt;/STRONG&gt;Outdated or redundant scripts can be deleted with a click, keeping your library lean, relevant, and audit-friendly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Boost analyst understanding with Copilot – &lt;/STRONG&gt;Understanding unfamiliar scripts can slow down investigations. That’s where &lt;STRONG&gt;Microsoft &lt;/STRONG&gt;&lt;STRONG&gt;Security Copilot &lt;/STRONG&gt;comes in.&lt;/P&gt;
&lt;P&gt;Copilot automatically analyzes scripts in the library and provides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Summarized behavior descriptions&lt;/LI&gt;
&lt;LI&gt;Security-relevant insights&lt;/LI&gt;
&lt;LI&gt;Execution risk context&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This makes it easier for analysts—especially those new to a team or handling inherited tools—to assess what a script does before running it, reducing errors and increasing confidence.&lt;/P&gt;
&lt;H4&gt;Get started today&lt;/H4&gt;
&lt;P&gt;You can access the Library Management experience from the &lt;STRONG&gt;live response &lt;/STRONG&gt;&lt;STRONG&gt;page&lt;/STRONG&gt; in the Microsoft Defender portal. Start uploading your investigation tools, explore script previews, and let Copilot assist in surfacing the intent and behavior of your scripts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;</description>
      <pubDate>Tue, 17 Feb 2026 17:52:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/introducing-library-management-in-microsoft-defender/ba-p/4494434</guid>
      <dc:creator>amibarayev</dc:creator>
      <dc:date>2026-02-17T17:52:18Z</dc:date>
    </item>
    <item>
      <title>Ignite 2025: Microsoft Defender now prevents threats on endpoints during an attack</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ignite-2025-microsoft-defender-now-prevents-threats-on-endpoints/ba-p/4470805</link>
      <description>&lt;P&gt;This year at Microsoft Ignite, Microsoft Defender is announcing exciting innovations for endpoint protection that help security teams deploy faster, gain more visibility, and proactively block attackers during active attacks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Predictive shielding:&lt;/STRONG&gt; Defender is the first security solution to not only respond instantly during an attack but also jump ahead of attackers, predicting and preventing the next move before it happens with just-in-time hardening controls that block specific attacker techniques to protect critical assets.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Custom data collection:&lt;/STRONG&gt; &lt;SPAN data-teams="true"&gt;Defender is now the only endpoint protection solution that allows data-hungry security teams to meet specific telemetry needs by optimizing their data collection right within the Defender portal, without the need to rely on fragmented and siloed solutions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Expanded Defender support for legacy Windows devices:&lt;/STRONG&gt; Better protect vulnerable legacy devices with consistent OS support of Microsoft Defender capabilities across Windows 7 &amp;amp; Windows 2008 R2 and higher.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Defender deployment tool:&lt;/STRONG&gt; Streamline the onboarding process with a lightweight tool that dynamically adapts to the operating system, delivering healthy endpoint security to a diverse estate of Windows and Linux devices.&lt;/LI&gt;
&lt;/UL&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=jDRmPoXIaL8/1763478450033" data-video-remote-vid="https://www.youtube.com/watch?v=jDRmPoXIaL8/1763478450033" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjDRmPoXIaL8&amp;amp;type=text%2Fhtml&amp;amp;schema=google&amp;amp;display_name=YouTube&amp;amp;src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FjDRmPoXIaL8" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;&lt;EM&gt;&lt;SPAN data-olk-copy-source="MailCompose"&gt;Video: Check out what's new in endpoint protection with Defender&lt;/SPAN&gt;&lt;/EM&gt;&lt;/div&gt;
&lt;H3&gt;Jump ahead of attackers: autonomous defense, real results&lt;/H3&gt;
&lt;P&gt;&lt;A href="http://Aka.ms/disrupt-ebook" target="_blank" rel="noopener"&gt;Automatic attack disruption&lt;/A&gt; is a capability unique to Microsoft Defender that contains attacks wherever they appear in your environment. It automatically detects and disrupts in-progress attacks with over 99% confidence, disrupting ransomware in an average of 3 minutes. In recent months, it disabled nearly half a million compromised accounts while saving over 270,000 devices.&lt;/P&gt;
&lt;P&gt;But today’s landscape is relentless: over 80% of advanced attacks are multi-stage and persistent, forcing defenders to be perfect over and over again. Even in the face of this incessant threat, the industry-wide approach of reactively responding to attacks is accepted as the best we can do. Until now.&lt;/P&gt;
&lt;P&gt;Today we are thrilled to move the bounds of endpoint protection by introducing &lt;STRONG&gt;predictive shielding&lt;/STRONG&gt;, a groundbreaking, &lt;EM&gt;proactive&lt;/EM&gt; capability of attack disruption.&lt;/P&gt;
&lt;P&gt;It acts in two steps:&lt;/P&gt;
&lt;P&gt;1. As soon as a compromised asset is contained, Defender&amp;nbsp;&lt;STRONG&gt;predicts&lt;/STRONG&gt; the attack paths and tactics the adversary will use next, in many cases narrowing down tens of thousands of possible pathways to just a few with the highest likelihood.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Image 1: Defender predicts the path and tactics an attacker will use&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;2. Then, it jumps ahead of the attacker and &lt;STRONG&gt;shields&lt;/STRONG&gt; those pathways by using just-in-time hardening methods, giving the attacker nowhere to go.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Image 2: Defender shields the path with just-in-time hardening tactics&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;So how can Defender do this when no one else can? It comes down to a combination of our unique visibility, leading threat intelligence, and AI-powered innovation. Defender uses AI technology to analyze the attack as it’s happening, identifying patterns of known attackers based on Microsoft’s deep threat intelligence, and then applies that to our unique understanding of the organization’s environment based on graph insights and integration as part of the Microsoft platform. With all this context, Defender can identify common attack techniques, which assets they’re trying to get to, and how they’ll try to get there.&lt;/P&gt;
&lt;P&gt;Based on these insights, Defender deploys innovative hardening capabilities that block specific attacker tactics and turn on as the attack is underway, just before an attacker attempts to use those tactics. Today we are starting with hardening capabilities seen in sophisticated ransomware campaigns, including group policy objects (GPO), safe mode reboot for tampering, and domain account compromise.&lt;/P&gt;
&lt;P&gt;While the precision of predictive shielding allows us to block operations surgically, security teams remain in command, with full visibility and control. All collected data and predictive shielding actions are available for investigation in the Defender portal, with controls that allow security teams to turn off hardening tactics with one click.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Image 3: The Defender portal provides full visibility into predictive shielding actions, with the option to turn them off&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Ready to see the future of autonomous defense? Join us online or in person for our&amp;nbsp;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK240" target="_blank" rel="noopener"&gt;Microsoft Ignite session on November 20&lt;SUP&gt;th&lt;/SUP&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;See the data you want to see, right in Defender&lt;/H3&gt;
&lt;P&gt;Security teams today are data savvy and are always looking for full visibility into their telemetry. Defender has long provided over 200 types of raw event types, each enriched with numerous properties and accessible through the threat hunting experience in the Defender portal. But each organization has unique data requirements, so many security teams use complex add-on products to collect and analyze additional data, contributing to the already overwhelming number of solutions they’re using.&lt;/P&gt;
&lt;P&gt;That’s why today we’re announcing the ability to collect and hunt across custom data right within the Defender portal. You can now easily build custom data collection rules based on your organization’s specific needs using natural language; no PhD required! We are releasing several new data types that can be collected, for example the highly requested AMSI for hunting over script content, and Kerberos for hunting auth-based and network attacks.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Image 4: Easily create custom data collection rules in the Defender portal&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This truly integrated custom data offering is possible thanks to Microsoft’s platform approach, as the additional telemetry can be collected and analyzed via Defender and stored via Microsoft Sentinel. This expansion puts you in complete control of any customized, add-on data, including exactly which data types are collected and how long they are stored. No other security solution has fully integrated and customizable telemetry collection and analysis.&lt;/P&gt;
&lt;H3&gt;Expanded support for Windows 7 and 2008 R2&lt;/H3&gt;
&lt;P&gt;Upgrading to the latest versions of each operating system as soon as possible is critical to optimize your security, but we understand that this is simply not realistic for many organizations. Our data shows that more than 90% of enterprises continue to have at least some legacy devices in their environment. Attackers know they present gaps in even the tightest security posture. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;That’s why today we are improving Defender’s coverage with expanded support for Windows 7 and Windows 2008 R2 to help you keep your legacy systems protected. We know that many organizations have Windows 7 and 2008 R2 in their environments, and it’s a critical milestone for us to support customers in bringing a consistent endpoint protection capability set across OS versions with Microsoft Defender.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Image &lt;/EM&gt;&lt;EM&gt;5: Operating system coverage with Microsoft Defender&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This new release further expands Defender support to the broad set of Windows, macOS, iOs, Android, and Linux versions listed in image 5. We’re committed to meeting you where you are to help you protect the most vulnerable points in your environment, so we are always evaluating demand and will continue to expand our coverage moving forward.&lt;/P&gt;
&lt;H3&gt;Simplified deployment for Windows and Linux&lt;/H3&gt;
&lt;P&gt;Organizations are faced with the challenge of securing diverse device fleets spanning multiple operating systems, hardware configurations, and user scenarios. Historically, the more diverse your operating system estate, the more complex your onboarding process, because it often requires a combination of endpoint management solutions like Microsoft Intune, but also scripts, downloads, and multiple manual installations to ensure coverage.&lt;/P&gt;
&lt;P&gt;To help security teams onboard simply and securely, we’ve built new Defender deployment tools for Windows and Linux, which handle the entire process for you. Just download a single package and it will dynamically adapt to the operating system, take care of prerequisites, and install the latest version of Defender available as needed for older devices that don’t have it already built in. The Defender deployment tools eliminate friction, automate tricky steps, and provide predictability throughout the onboarding journey.&lt;/P&gt;
&lt;P&gt;They also have several controls built in that allow you to test for issues before onboarding and can accommodate complex scenarios like virtual desktop infrastructure. For customers of Microsoft Intune and Microsoft Defender for Cloud, the Defender deployment tools work in tandem, available to use for legacy systems or complex scenarios.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This release is the latest step in our journey to secure diverse device environments and sets the foundation for a unified and intuitive deployment experience—one that meets the demands of modern IT and security teams across organizations of all sizes.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We hope you’ll join us online or in San Francisco for our &lt;/STRONG&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK240" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Ignite session on November 20&lt;SUP&gt;th&lt;/SUP&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;to learn more about these and other exciting announcements in Defender’s industry-leading endpoint protection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Featured sessions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK240" target="_blank" rel="noopener"&gt;BRK240: Endpoint security in the AI era: What's new in Defender&lt;/A&gt;; November 20&lt;SUP&gt;th&lt;/SUP&gt; 9:45am PT&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/THR747" target="_blank" rel="noopener"&gt;THR747: Disrupt ransomware attacks before harm occurs with Microsoft Defender&lt;/A&gt;; November 21&lt;SUP&gt;st&lt;/SUP&gt; 9:30am PT&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://ignite.microsoft.com/en-US/sessions/BRK241" target="_blank" rel="noopener"&gt;BRK241: Microsoft Defender: Building the agentic SOC with guest Allie Mellen&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;; November 19&lt;/SPAN&gt;&lt;SUP style="color: rgb(30, 30, 30);"&gt;th&lt;/SUP&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; 9:00am PT&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://ignite.microsoft.com/en-US/sessions/BRK246" target="_blank" rel="noopener"&gt;BRK246: Blueprint for building the SOC of the future&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;November 19&lt;/SPAN&gt;&lt;SUP style="color: rgb(30, 30, 30);"&gt;th&lt;/SUP&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; 4:00pm PT&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Related resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-xdr/shield-predict-threats" target="_blank" rel="noopener"&gt;Learn more about predictive shielding&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/custom-data-collection" target="_blank" rel="noopener"&gt;Learn more about custom data collection&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/defender-endpoint/onboard-downlevel" target="_blank" rel="noopener"&gt;Learn more about Defender endpoint security for Windows 7 SP1 and Windows Server 2008 R2 SP1 devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-endpoint/defender-deployment-tool-windows" target="_blank" rel="noopener"&gt;Deploy Microsoft Defender on Windows devices using the Defender deployment tool&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-endpoint/linux-install-with-defender-deployment-tool" target="_blank" rel="noopener"&gt;Deploy Microsoft Defender on Linux devices using the Defender deployment tool&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To learn more about Defender’s endpoint protection, visit our&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website.&lt;/A&gt;&amp;nbsp;Bookmark &lt;A href="https://techcommunity.microsoft.com/category/microsoft-defender-for-endpoint/blog/microsoftdefenderatpblog" target="_blank" rel="noopener"&gt;our blog&lt;/A&gt; to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 21:50:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ignite-2025-microsoft-defender-now-prevents-threats-on-endpoints/ba-p/4470805</guid>
      <dc:creator>clairelevy</dc:creator>
      <dc:date>2025-11-20T21:50:11Z</dc:date>
    </item>
    <item>
      <title>End of Windows 10 Support: What Defender Customers Need to Know</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/end-of-windows-10-support-what-defender-customers-need-to-know/ba-p/4461349</link>
      <description>&lt;P&gt;As of today, October 14, 2025, Microsoft is officially ending support for Windows 10. This means that Windows 10 devices will no longer receive security or feature updates, nor technical support from Microsoft. While these devices will continue to operate, the lack of regular security updates increases vulnerability to cyber threats, including malware and viruses. Applications running on Windows 10 may also lose support as the platform stops receiving updates.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Will Defender continue to protect Windows 10 devices?&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Defender supports a range of legacy systems, including Windows 10. (&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/minimum-requirements#windows-versions-supported-by-defender-for-endpoint" target="_blank" rel="noopener"&gt;See here for a full list of supported operating systems&lt;/A&gt;.) Microsoft Defender will continue to provide detection and protection capabilities to the extent possible on Windows 10 and other legacy systems. Keep in mind that security solutions on legacy systems are inherently less secure and may not be able to receive all new features, so please review the next section for important actions you can take.&lt;/LI&gt;
&lt;LI&gt;For Windows 10 customers without Defender, Microsoft will continue to provide security intelligence updates for the built-in Microsoft Defender Antivirus protection through October 2028. Of course, Defender Antivirus alone isn't a comprehensive risk mitigation posture without Microsoft Defender detection and response deployed across your digital estate.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;What should customers do to protect their Windows 10 devices?&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Upgrade to Windows 11:&lt;/STRONG&gt;&lt;BR /&gt;Moving to Windows 11 is strongly recommended for PCs eligible to upgrade. Windows 11 delivers the latest security features, improved performance, and ongoing support at no additional cost. This is the best way to ensure your endpoints remain protected and compliant. Devices running Windows 10 will be more vulnerable, even with ongoing security intelligence updates (SIUs).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Extended security update (ESU) program:&lt;/STRONG&gt;&lt;BR /&gt;If upgrading isn’t immediately possible, Microsoft offers an ESU program for Windows 10. The ESU program provides critical and important security updates but does not include new Windows features or technical support.
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Enterprise customers&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; can purchase ESU for up to three years or receive it at no additional cost with a Windows 365 subscription.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Cloud and virtual environments:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; Windows 10 devices accessing Windows 11 Cloud PCs via Windows 365 or Virtual Machines are entitled to ESU at no extra cost, with automatic updates.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Consumer customers&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; have options to enroll for one year of ESU, including free enrollment methods in certain regions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For further guidance, check out the posts below or connect with your Microsoft account team.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2FEN-US%2Fwindows%2Fend-of-support%3Ficid%3DSSM_Search_Windows10Endofsupport_Surface_CTA2%26r%3D1&amp;amp;data=05%7C02%7Cclairelevy%40microsoft.com%7C4ee4051be7084171eaac08ddfc6de8d7%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638944271958205169%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=S0l3cqfkZruk6Vzrn%2BmBobiStEyfEKf1yCMQFPIRkQQ%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;End of support for Windows 10, Windows 8.1, and Windows 7 | Microsoft Windows&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fblogs.windows.com%2Fwindowsexperience%2F2024%2F10%2F31%2Fhow-to-prepare-for-windows-10-end-of-support-by-moving-to-windows-11-today%2F&amp;amp;data=05%7C02%7Cclairelevy%40microsoft.com%7C4ee4051be7084171eaac08ddfc6de8d7%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638944271958222025%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=Prgj2vHNp%2FmoJ%2Fg9wK0SbaQg9Q5yIVUZvp51V7Z3cGo%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;How to prepare for Windows 10 end of support by moving to Windows 11 today | Windows Experience Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fwindows%2Fwhats-new%2Fextended-security-updates&amp;amp;data=05%7C02%7Cclairelevy%40microsoft.com%7C4ee4051be7084171eaac08ddfc6de8d7%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638944271958343460%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=p6hv5Vaa9vEVx%2FzAGP1JbiUQ7IV1IdIpATE0mVwmdxs%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Extended Security Updates (ESU) program for Windows 10 | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To learn more about Microsoft Security solutions, visit our&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt;&amp;nbsp;Bookmark the&amp;nbsp;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt;&amp;nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 16:26:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/end-of-windows-10-support-what-defender-customers-need-to-know/ba-p/4461349</guid>
      <dc:creator>clairelevy</dc:creator>
      <dc:date>2025-10-14T16:26:01Z</dc:date>
    </item>
    <item>
      <title>Multi-tenant endpoint security policies distribution is now in Public Preview</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/multi-tenant-endpoint-security-policies-distribution-is-now-in/ba-p/4439929</link>
      <description>&lt;P&gt;We’re excited to announce a key milestone in Defender’s multi-tenant management journey—Microsoft Defender for Endpoint security policies can now be distributed across multiple tenants from the Defender multi-tenant portal. This capability empowers security teams to manage policies at scale, ensuring consistency and saving valuable time.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is content distribution?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Content distribution is a powerful Defender feature that enables scalable management of content across tenants. With this capability, you can create content distribution profiles in the multi-tenant portal that allow you to seamlessly replicate existing content—such as custom detection rules and now, endpoint security policies—from a source tenant to designated target tenants. Once distributed, the content runs on the target tenant, enabling centralized control with localized execution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it works&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;Security policies are now a selectable content type when creating a distribution profile.&lt;/LI&gt;
&lt;LI&gt;Simply choose existing policies from your home tenant and add them to the distribution profile. You can also decide which Microsoft Entra group(s) will be applied as scope. Policy targeting will be based on the Entra device groups that exist in every tenant, and you select the relevant groups for each tenant.&lt;/LI&gt;
&lt;LI&gt;Upon completion, policies are automatically distributed to the selected tenants and are applied on the targeted machines.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;Distributed policies also appear in a hierarchical view, with the original policy serving as the parent. You can find the policies that were distributed from the tenant under the original policy. This appears on the endpoint security policies page within multi-tenant management.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The&amp;nbsp;last distribution status&amp;nbsp;for the original policy reflects the overall status of its distributed copies, and the&amp;nbsp;tenants&amp;nbsp;and&amp;nbsp;tenant groups&amp;nbsp;sections indicate the recipients of the policy.&lt;/P&gt;
&lt;P&gt;At any time, you can update the policies, tenants, scope or any other settings, and sync to apply these changes.&lt;/P&gt;
&lt;P&gt;This new capability enables consistency (maintaining uniform security posture across tenants), efficiency (eliminating manual duplication and reducing operational overhead), and scalability (easily expanding coverage as the tenant landscape grows).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;FAQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What pre-requisites are required?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Access to more than one tenant with Microsoft Defender for Endpoint, with delegated access via Azure B2B or GDAP (CSP Partners only), using the multi-tenant management capability.&lt;/LI&gt;
&lt;LI&gt;A subscription to Microsoft 365 E5 or Office E5.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What permissions are needed to distribute MDE security policies?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;To access endpoint security policies, users require the security administrator role in each relevant tenant.&lt;/LI&gt;
&lt;LI&gt;To distribute content using multi-tenant management content distribution, the Security settings (manage) or Security Data Basic (read) permission is required. Both roles are assigned to the Security Administrator and Security Reader Microsoft Entra built-in roles by default.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Can I update or expand distribution profiles later?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Yes. You can add more content, include additional tenants, or modify scopes as needed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;For more information, see&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/unified-secops-platform/mto-distribution-profiles" target="_blank" rel="noopener"&gt;Content distribution in multitenant management&lt;/A&gt;. To get started, navigate to the&amp;nbsp;&lt;A class="lia-external-url" href="https://mto.security.microsoft.com/contentdistribution" target="_blank" rel="noopener"&gt;Content distribution page&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Defender's endpoint protection, check out our &lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank"&gt;website&lt;/A&gt; and &lt;A href="https://youtu.be/BUGoxeoSffs" target="_blank"&gt;video&lt;/A&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Security solutions, visit our &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; Bookmark the &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 07 Aug 2025 16:17:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/multi-tenant-endpoint-security-policies-distribution-is-now-in/ba-p/4439929</guid>
      <dc:creator>tomasbeerthuis</dc:creator>
      <dc:date>2025-08-07T16:17:41Z</dc:date>
    </item>
    <item>
      <title>Maintain connectivity for essential services with selective network isolation</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/maintain-connectivity-for-essential-services-with-selective/ba-p/4422938</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Network isolation&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; refers to how Microsoft Defender for Endpoint restricts a compromised device’s communication within the network in order to contain threats and prevent lateral movement. But oftentimes when isolating devices, certain critical services like management tools or security solutions need to remain operational.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That's why Defender for Endpoint has launched selective isolation exclusions, which allow you to exclude specific devices, processes, IP addresses, or services from unilateral network isolation actions. This allows essential functions (e.g., remote remediation or monitoring) to continue in the event of a breach, while limiting broader network exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Isolation Modes&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;There are two modes available:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="%1." data-font="Aptos" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Full isolation&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI data-leveltext="%1." data-font="Aptos" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;In this mode, the device is completely isolated from the network, and no exceptions are allowed. All traffic is blocked, except for essential communications with the Defender agent.&lt;/LI&gt;
&lt;LI data-leveltext="%1." data-font="Aptos" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;Exclusions cannot be applied in full isolation mode. This is the most secure option, suitable for scenarios where a high level of containment is necessary.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="%1)" data-font="" data-listid="17" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1)&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;,&amp;quot;469778510&amp;quot;:&amp;quot;numbered&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;[New] Selective isolation&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI data-leveltext="%1)" data-font="" data-listid="17" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1)&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;,&amp;quot;469778510&amp;quot;:&amp;quot;numbered&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;Selective isolation allows administrators to apply exclusions to ensure that critical tools and network communications can still function, even while maintaining the device’s isolated state.&lt;/LI&gt;
&lt;LI data-leveltext="%1)" data-font="" data-listid="17" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1)&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;,&amp;quot;469778510&amp;quot;:&amp;quot;numbered&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;⚠️&amp;nbsp;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Note:&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Any exclusion weakens device isolation and increases security risks. To minimize risk, configure exclusions only when absolutely necessary. Regularly review and update exclusions to align with security policies.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To get started, r&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ead the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/isolation-exclusions" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;isolation exclusions documentation&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Learn more&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:150}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Security solutions, visit our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:150}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 16:29:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/maintain-connectivity-for-essential-services-with-selective/ba-p/4422938</guid>
      <dc:creator>amibarayev</dc:creator>
      <dc:date>2025-06-25T16:29:44Z</dc:date>
    </item>
    <item>
      <title>Microsoft’s participation in MITRE ATT&amp;CK® Evaluations: Enterprise 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-s-participation-in-mitre-att-ck-evaluations-enterprise/ba-p/4422639</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft has a long-standing&amp;nbsp;relationship with MITRE and&amp;nbsp;holds&amp;nbsp;deep respect for the&amp;nbsp;unique&amp;nbsp;role that&amp;nbsp;the organization&amp;nbsp;plays&amp;nbsp;within the&amp;nbsp;security ecosystem.&amp;nbsp;&amp;nbsp;MITRE&amp;nbsp;ATT&amp;amp;CK&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;®&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Evaluations&amp;nbsp;have&amp;nbsp;been instrumental in helping&amp;nbsp;us&amp;nbsp;improve our products.&amp;nbsp;We are grateful for their&amp;nbsp;invaluable&amp;nbsp;contributions&amp;nbsp;in advancing security&amp;nbsp;for all.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;After extensive deliberation, Microsoft has decided to not participate in the evaluation this year. This decision allows us to focus all our resources on the Secure Future Initiative and on delivering product innovation to our customers. We look forward to continuing our collaboration with the MITRE team and wish them all the best for this year’s evaluation.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-s-participation-in-mitre-att-ck-evaluations-enterprise/ba-p/4422639</guid>
      <dc:creator>KarthikSelvaraj</dc:creator>
      <dc:date>2025-06-13T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Behavior monitoring is now generally available for Microsoft Defender for Endpoint on macOS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/behavior-monitoring-is-now-generally-available-for-microsoft/ba-p/4415697</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enhancing macOS security with behavior monitoring&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As attackers become more sophisticated in today’s rapidly evolving threat landscape, security strategies must continue to innovate to keep pace. For instance, static signature-based approaches to malware detection are useful but not enough. Rather, when combined with more dynamic forms of detection like behavior monitoring, your environment is better equipped to block new and evolving threats. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Behavior monitoring observes how software behaves in real-time to detect and analyze potential threats based on the behavior of the applications, daemons, and files within your system. Behavior monitoring is a cornerstone of Microsoft Defender’s cloud-based protection strategy. A wide array of our most advanced protection capabilities rely on behavior monitoring’s cloud models to not only detect but also effectively respond to complex and evolving threats.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;Today, we’re excited to announce that behavior monitoring is now generally available on macOS, and is rolling out broadly over the course of the next few weeks.&lt;/EM&gt; Like with Windows and Linux, behavior monitoring for macOS extends Defender for Endpoint’s protection beyond static signatures to track the larger scale relationships between processes.&amp;nbsp; This capability significantly enhances the early detection of suspicious or malicious activities by spotting unusual process interactions and patterns.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="none"&gt;What does this mean for customers?&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By extending this critical technology to macOS, customers will benefit from a consistent level of protection across all of their devices. Behavior monitoring introduces a rich new stream of telemetry that helps lay important groundwork for advancing innovative protections against threats targeting macOS users. In the future, it will be possible to build custom logic based on the process and file system events supported by behavior monitoring, equipping you with a more dynamic and tailored way to secure your endpoints.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Real-world example of behavior monitoring&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Let's understand the significance of this feature. The Atomic macOS Stealer (AMOS) is a sophisticated macOS malware engineered to steal sensitive information from systems. It targets a broad spectrum of data, including Keychain passwords, system information, files from desktop and documents folders, macOS user passwords, browser data (such as cookies and login credentials), and cryptocurrency wallets. To evade detection, AMOS employs obfuscation techniques like XOR encryption, making its payloads challenging to identify through static analysis alone. Due to its advanced nature, effective detection of AMOS necessitates dynamic analysis and behavior detection methods, rather than relying solely on static signature-based approaches.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Behavior monitoring alerts are displayed in the &lt;/SPAN&gt;&lt;A href="https://security.microsoft.com/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender XDR portal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN data-contrast="none"&gt;alongside all other alerts, enabling effective investigation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;The following image in the Microsoft Defender XDR portal shows that Defender detected and terminated a suspicious action using behavior monitoring on macOS.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;The following image is an alert in the Microsoft Defender XDR portal that shows that a suspicious action was blocked using behavior monitoring technology.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To experience the Mac antivirus behavior monitoring and blocking, users will need a minimum version Microsoft Defender for Endpoint, which is &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;101.25032.0006.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN data-contrast="none"&gt;Availability&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Our macOS behavior monitoring and blocking capabilities are available on the following major versions of Mac currently supported by Microsoft Defender for Endpoint:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-style: italic;" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;macOS Ventura (13)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-90,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="font-style: italic;" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;macOS Sonoma (14)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-90,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="font-style: italic;" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;macOS Sequoia (15)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-90,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Behavior Monitoring is being rolled out automatically following our &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-for-endpoint%e2%80%99s-safe-deployment-practices/4220342" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;afe &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;eployment &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ractices (SDP)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; per the schedule below.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Channel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Staring Date&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;App Version&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;External&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;3/31/2025&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;gt; 101.25042.0002&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Production&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;5/19/2025&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;gt; 101.25032.0006&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-teams="true"&gt;Once fully deployed, behavior monitoring will be on by default for everyone.&lt;/SPAN&gt; You can confirm your device’s enrollment status by checking the output of &lt;SPAN class="lia-text-color-20"&gt;&lt;EM&gt;&lt;STRONG&gt;mdatp health --details&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-text-color-20"&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;features&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; in your terminal.&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If your device is not yet enabled automatically, you can enable it manually. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enabling Behavior Monitoring&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For customers that need to change the settings of behavior monitoring, you can use &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos#intune-deployment" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; or a &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos#jamf-deployment" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-fontsize="12" data-ccp-charstyle="Hyperlink"&gt;rd&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; party MDM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for enterprises or &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos#manual-deployment" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;manually&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; using &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-20"&gt;&lt;EM&gt;sudo mdatp config behavior-monitoring&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; for a trial deployment.&amp;nbsp; Support for behavior monitoring in Defender for Endpoint’s &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/mde-security-settings-management" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ecurity &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ettings &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;anagement&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; experience is expected this summer.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN data-contrast="auto"&gt;Additional resources for securing &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;macOS&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; with behavior monitoring&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The following resources can help you optimize your macOS security and behavior monitoring settings:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Refer to &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the following article&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for more details about configurations related to behavior monitoring.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Monitor the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/mac-whatsnew" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;What's new in Microsoft Defender for Endpoint on Mac&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; page for upcoming announcements.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/enhancing-linux-antivirus-with-behavior-monitoring-capabilities/2226705" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Read this blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; t&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="auto"&gt;o learn more about how behavior monitoring works on Linux.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We welcome your feedback and look forward to hearing from you! You can submit feedback through the &lt;/SPAN&gt;&lt;A href="https://security.microsoft.com/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender XDR portal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Learn more&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Security solutions, visit our &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; Bookmark the &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:-630,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:60,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 20:17:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/behavior-monitoring-is-now-generally-available-for-microsoft/ba-p/4415697</guid>
      <dc:creator>JoshBregman</dc:creator>
      <dc:date>2025-06-10T20:17:04Z</dc:date>
    </item>
    <item>
      <title>Manage global exclusion policies for Linux across both AV and EDR</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/manage-global-exclusion-policies-for-linux-across-both-av-and/ba-p/4420127</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Create and manage global &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;exclusions for &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Linux&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;G&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;lobal exclusions for &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;Microsoft Defender for Endpoint on Linux are now generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;This will allow&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; security teams to &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;create and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; manage exclusion&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; that apply to&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;both &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;ntivirus&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; (AV) and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;ndpoint &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;etection and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;esponse&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; (EDR&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;)&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;—&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;helping reduce false positives, improve performance, and streamline security operations on Linux servers.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335557856&amp;quot;:16448250,&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;Many organizations rely on exclusions to &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;maintain&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;optimal&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; performance and ensure compatibility—especially in Linux server environments running custom applications or handling high&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; input/output&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; workloads. Until now, the absence of a unified exclusion scope across both AV and EDR made it challenging to tackle performance issues and avoid disruptions &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;to&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; trusted software due to false positives.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335557856&amp;quot;:16448250,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;With global exclusions, organizations can now effortlessly exclude specific files, folders, and processes from both AV and EDR using a single, centralized configuration—ensuring consistent protection, improved accuracy, and better performance across their Linux workloads.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335557856&amp;quot;:16448250,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN data-contrast="none"&gt;Key benefits&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="19" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Unified scope for antivirus + endpoint detection and response&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: Apply exclusions across both antivirus and endpoint detection and response using a single exclusion scope called “Global”.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation of performance issues&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Helps address performance issues—such as high CPU and memory usage—by excluding noisy processes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233279&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="20" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Reduced false positives:&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Avoid flagging known and trusted files or custom applications unique to your environment. By excluding trusted files and processes—such as Tanium&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;used in endpoint management—you can avoid incorrect detections and focus on high-fidelity signals.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="20" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Centralized, scalable management:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Configure exclusions via security settings management using the Defender portal, Microsoft Intune, or JSON-based policies.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;How it works&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233279&amp;quot;:true,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Global exclusions in Microsoft Defender for Endpoint for Linux are applied at the sensor level. This early-stage filtering helps eliminate noise from trusted sources before any pre-processing by antivirus or &lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;ndpoint &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;etection and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;esponse &lt;/SPAN&gt;&lt;/SPAN&gt;engines. By default, these exclusions apply to real-time protection and passive mode, but not to on-demand custom scans. Here’s the summary of how it works:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Scope&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: Applies to both real-time protection and EDR detections on Linux. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;It does not impact on-demand scans.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240,&amp;quot;469777462&amp;quot;:[720],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Supported types&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: You can exclude files, folders and processes&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240,&amp;quot;469777462&amp;quot;:[720],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Configuration options&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240,&amp;quot;469777462&amp;quot;:[720],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender portal: &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Use the built-in security settings management experience.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"&gt;Microsoft Intune&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;: Use the endpoint security blade to define and deploy exclusion policies.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="22" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"&gt;JSON-based policies&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;: For advanced deployments, exclusions can be defined in managed JSON and deployed via configuration management tools.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240,&amp;quot;469777462&amp;quot;:[1440],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;This flowchart shows when and where global exclusions are applied in the context of Microsoft Defender for Endpoint on Linux.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Getting started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For detailed guidance on how to configure, validate, and manage global exclusions&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; please refer to our documentation: &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/linux-exclusions" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Configure and validate exclusions for Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To start using global exclusions for Microsoft Defender for Endpoint on Linux, please upgrade to the latest version &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;101.24092.0001 &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;or above.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;</description>
      <pubDate>Thu, 05 Jun 2025 16:36:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/manage-global-exclusion-policies-for-linux-across-both-av-and/ba-p/4420127</guid>
      <dc:creator>Rutuja_dange</dc:creator>
      <dc:date>2025-06-05T16:36:57Z</dc:date>
    </item>
    <item>
      <title>Discover how automatic attack disruption protects critical assets while ensuring business continuity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/discover-how-automatic-attack-disruption-protects-critical/ba-p/4416597</link>
      <description>&lt;P aria-level="1"&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Protecting&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 1"&gt;c&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;ritical &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;sset&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;s&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:322,&amp;quot;335559739&amp;quot;:322}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Traditional security solutions often operate in a one-size-fits-all alert model that treats every detection equally, regardless of how important the asset is. But not all assets are equal. Critical assets are systems governing access, identity, or sensitive data. They are essential to an organization’s operations and security, for example, domain controllers, cloud connectivity gateways, key management servers, and others. If attackers compromise these assets, business continuity suffers at great scale. As these systems typically have less routine activity, any alert on them is far more significant.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat actors specifically target these high-value systems, meaning that even weaker signals need to be properly investigated. With short-staffed SOC teams, it has historically been a challenge to respond to these types of signals effectively. Given assets like domain controllers are the backbone to an organization’s daily operations, protecting critical infrastructure means proactively stopping adversaries &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;before&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; they inflict damage. So how do security solutions help SOC teams effectively protect critical assets while ensuring business continuity?&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To help security teams meet this challenge, Microsoft Defender developed automatic attack disruption: a built-in self-defense capability that identifies &amp;amp; disrupts multi-domain attacks in near real time to prevent further damage across the organization. We recently &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/04/09/how-cyberattackers-exploit-domain-controllers-using-ransomware/?msockid=1a665e69633567953e7a4b2062b1666a" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;announced&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; how we protect domain controllers against ransomware as the latest attack disruption innovation.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Behind the scenes, attack disruption uses a critical asset framework to achieve this outcome. This framework is developed from the latest threat research and tested internally within Microsoft’s security infrastructure to provide the context needed to differentiate true threats from noise for critical assets, empowering organizations to act decisively when it matters most. Using the native integration between Microsoft Defender for Endpoint and Microsoft Security Exposure Management, we can automatically identify critical assets in your environment and apply deep contextual insights based on each asset’s unique threat profile to disrupt attacks accordingly.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This blog post dives into how this framework drives real impact, its core components, innovative methodology, and how it helps ensure that organizations are proactive and efficient in their defense strategy specifically for critical asset protection.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Real world impact&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:299,&amp;quot;335559739&amp;quot;:299}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By applying the critical asset framework, Microsoft Defender was able to disrupt attacks targeting high-value assets several days earlier in the kill chain in 40% of triggered incidents. This early intervention significantly reduces attacker dwell time, helping prevent impact and limit damage. Additionally, in another 40% of incidents, risk-based contextual insights transformed weak signals into clear, actionable disruption opportunities. These were unique incidents, false negatives in the past, that are now being surfaced and mitigated for the first time.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;U&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Neutralizing a human-operated attack on a global enterprise&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;’&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;s domain controller&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this scenario, a global enterprise was running multiple endpoint detection &amp;amp; response vendors in their environment, including Microsoft Defender for Endpoint. The organization was targeted by an advanced, human-operated attack on their domain controllers. Only Microsoft’s solution was able to stop the attack thanks to Defender’s early detection and disruption capabilities. The threat was neutralized before any damage could be inflicted, demonstrating the necessity of&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/automatic-attack-disruption" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;automatic attack&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; disruption&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; in the fight against ransomware. Meanwhile, critical assets onboarded to the other vendor were impacted.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Attack story showing automatic attack disruption saving domain controllers onboarded to Microsoft Defender for Endpoint whereas those onboarded to a different EDR solution were encrypted.&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Core principles for protecting critical assets&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Now that you’ve seen how effective attack disruption is for protecting critical assets, let’s take a look at the core principles shaping our framework:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Prioritization and classification:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; By classifying assets based on their criticality and role we ensure that disruption actions are triggered precisely where they matter most. With fewer benign events on critical systems, every detection is more likely to reflect a genuine threat, enabling faster, more targeted responses that directly enhance client security and operational confidence.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Proactive, real-time defense:&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Our context-driven approach enables early detection and disruption of threats, often stopping attacks days before they can cause significant harm.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Adaptive and scalable:&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Although our initial focus has been on domain controllers, the framework is designed to be flexible and protect a variety of other critical assets such as cloud connectivity solutions and publicly connected devices, based on each asset’s unique behavioral context.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We take these principles and translate them into actionable detection and disruption actions tailored to protect critical assets from the sophisticated and persistent threats that they frequently face.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Under the hood of critical asset protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:299,&amp;quot;335559739&amp;quot;:299}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI data-leveltext="%1." data-font="" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Asset classification:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Our process starts by analyzing each asset’s role and criticality using Microsoft Security Exposure Management to identify and prioritize critical assets, guiding every disruption decision along the way.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="%1." data-font="" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;Detector integration and management:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;U&gt;Targeted detector selection:&lt;/U&gt;&amp;nbsp;&lt;SPAN data-contrast="auto"&gt;We have engineered a specialized set of detectors most relevant to high-value assets, g&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;uided by extensive asset-specific threat research&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;This ensures each critical asset is protected by detectors selected specifically for the threats it faces.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Automated quality evaluation:&lt;/U&gt;&lt;SPAN data-contrast="auto"&gt; Our system continuously assesses each detector’s signal-to-noise ratio and overall impact, deploying only those that meet our strict standards.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Integrated security platform:&lt;/U&gt;&amp;nbsp;&lt;SPAN data-contrast="none"&gt;A dedicated module orchestrates every step - from generating alerts and enriching them with context to automatically triggering the right containment or remediation action via one streamlined workflow.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Contextual disruption execution:&lt;/STRONG&gt; &lt;SPAN data-contrast="none"&gt;When a detector triggers on a critical asset, our framework immediately enriches the alert with detailed contextual telemetry. This enriched data is leveraged in several powerful ways. For example, events are correlated to accurately identify any impacted users - even when initial detections lack clear user data (such as when a malicious payload runs under the SYSTEM account via a service, where our framework traces the creator of the service). The framework also assesses remote activity to capture additional related entities, applying tailored threat lists specific to each asset type. These examples demonstrate how our context-driven approach transforms raw detections into precise, actionable intelligence that enable targeted responses like user containment and soon,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/automatic-attack-disruption-enhanced-containment-for-critical-assets-and-shadow-/4402157" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;IP containment for critical assets&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Where we’re heading&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As the threat landscape evolves, we continue investing in attack disruption’s ability to protect critical assets. Our roadmap includes:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Scaling through AI-driven behavioral coverage:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; We’re shifting from a detector-centric approach to an AI-driven model that continuously learns from vast volumes of telemetry and behavioral patterns. We’re shifting the framework to identify and disrupt threats dynamically, improving precision, expanding coverage, and adapting faster than static rules ever could.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;Extending asset coverage:&lt;/STRONG&gt; &lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Beyond domain controllers, upcoming iterations will include additional high-value assets such as Entra Connect Sync servers, internet-facing servers, SQLs servers, and more - providing comprehensive protection across your organization’s critical infrastructure.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;Deepening integration:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;This innovation has been made possible through the integration between Microsoft Defender for Endpoint and Microsoft Security Exposure Management, which provides advanced asset classification. Our ongoing partnership ensures we continue to innovate and deliver tailored solutions that address unique client needs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Conclusion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:299,&amp;quot;335559739&amp;quot;:299}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The ability to protect critical assets represents a paradigm shift in cybersecurity, moving from reactive alerting to proactive, context-aware disruption that prioritizes not just alerts, but the assets themselves. By recognizing that not all assets carry the same risk, our approach ensures that protection efforts are focused where they matter most, enabling true end-to-end defense. By integrating advanced asset classification and context-driven intelligence into our security platform, we’re not only protecting critical systems like domain controllers but also empowering customers with decisive, actionable insights.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As we continue to innovate, our commitment remains clear: to deliver intelligent, effective security solutions that safeguard your most vital assets against even the most advanced threats.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt; Learn more&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Explore these resources to stay updated on the latest automatic attack disruption capabilities and how we protect critical assets:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Learn more about &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender for Endpoint&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Read our latest security &lt;/SPAN&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2025%2F04%2F09%2Fhow-cyberattackers-exploit-domain-controllers-using-ransomware%2F&amp;amp;data=05%7C02%7Ccaroll%40microsoft.com%7C7e36b39165754d5909bb08dd76d9377c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638797397551756393%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=7yp1TNuwOgNibiVlJp8ADKyms8l9%2FCsKMWXoweIlKg4%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;blog &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;on how we protect against ransomware attacks using domain controllers.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Read about the &lt;/SPAN&gt;&lt;A href="https://aka.ms/containIP-HVA" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;new containment features&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Learn how attack disruption safeguards your domain controllers in this &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=BUGoxeoSffs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;video&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Check out our latest &lt;/SPAN&gt;&lt;A href="https://aka.ms/disruptinfo" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;infographic&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Read about &lt;/SPAN&gt;&lt;A href="https://aka.ms/disruptdocs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;automatic attack disruption&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Security solutions, visit our &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; Bookmark the &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 18:40:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/discover-how-automatic-attack-disruption-protects-critical/ba-p/4416597</guid>
      <dc:creator>DorFenigshtein</dc:creator>
      <dc:date>2025-05-27T18:40:02Z</dc:date>
    </item>
    <item>
      <title>Defender for Endpoint successfully passes the AV-Comparatives 2025 Anti-Tampering Test</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-endpoint-successfully-passes-the-av-comparatives/ba-p/4414153</link>
      <description>&lt;P aria-level="2"&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The rise of tampering&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; attacks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;In cybersecurity, anti-tampering &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;protection r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;efers to the &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;defensive measur&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;es designed to prevent unauthorized modifications to security system&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s, policies, and setting&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;When threat actors compromise an organization, they often start by tampering with security solutions&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; in an effort to&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;further exploit and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;achieve persistence within&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;the environment&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; Common tampering tactics include&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; disabling&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; or altering&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; antivirus and endpoint detection and response (EDR) tools&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;,&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; turning off real-time protection and security intelligence updates&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;editing &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;high-value &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;device and access policies, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and creating exclusions that allow malicious activities to go undetected. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;After having tampered successfully&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;attackers gain valuable time to install malicious tools, exfiltrate data, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;move laterally, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;launch&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; ransomware&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; attacks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:299,&amp;quot;335559739&amp;quot;:299}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;In recent years, Microsoft has observed a significant volume of attacks involving antivirus tampering. In May 2024 alone, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Defender XDR detected over 176,000 incidents involving tampering with security settings, impacting more than 5,600 organizations ¹&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;. On average, during that time frame, organizations that encountered&amp;nbsp;tampering activity saw over 31 attempts. Techniques observed by Microsoft include Windows Registry modifications, use of malicious tooling such as NSudo (Defeat Defender), Defender Control, Configure Defender, ToggleDefender, custom malicious PowerShell or batch scripts, and driver tampering.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Defender for Endpoint effectively thwarts tampering attacks&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Defender for Endpoint offers robust anti-tampering capabilities that protect against end-user and third-party security settings changes, even in the context of a privileged user.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; These built-in controls can prevent local and non-authorized remote administrators from altering critical settings at the organizational, platform, and device levels – you can even create specific rules for high-value device types such as domain controllers. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;This means that you are automatically protected against common tampering tactics used by attackers including the modification of registry settings, DLLs, file systems, and agents. On top of that, any attempt to create exclusions in your antivirus and EDR tools or to terminate or suspend your system processes and services will be thwarted. These settings&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; are on-by-default for all Defender for Endpoint customers, delivering comprehensive anti-tampering protection from day one.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;We are pleased to announce that AV-Comparatives has certified Microsoft Defender for Endpoint for &lt;/SPAN&gt;&lt;A href="https://www.av-comparatives.org/tests/anti-tampering-certification-microsoft-defender-for-endpoint-p2-license/?utm_source=ZohoCampaigns&amp;amp;utm_campaign=Anti-Tampering+Test++%E2%80%93+Press&amp;amp;utm_medium=email" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;successfully thwarting all tampering attemp&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; levied during the 2025 Anti-Tampering Test.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp; The test involved rigorous evaluation of security solutions to defend against sophisticated attack techniques aimed at disabling or bypassing protection mechanisms. This includes attempts to &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;disable or modify Windows kernel components and disable or terminate processes in the Windows user space. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Even under sustained attack (&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;various tests, tools, and procedures designed to penetrate our anti-tampering controls)&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;, Defender for Endpoint demonstrated its ability to maintain protection. This evaluation not only validates the effectiveness of our advanced tampering and defense evasion controls but also reinforces Defender for Endpoint’s position as a leader in endpoint detection and response.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Defender for Endpoint successfully thwarted 100% of the tampering attacks made against the categories shown above in AV-Comparatives 2025 Anti-Tampering Test&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Learn more&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Explore the following resources to learn more about how Defender for Endpoint defends against tampering attacks:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Protect security settings with tamper protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/tamper-resiliency" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Protect your organization from the effects of tampering&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;See additional evaluation results for Defender for Endpoint, demonstrating the industry-leading effectiveness of our endpoint security solution:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2024/09/25/microsoft-is-named-a-leader-in-the-2024-gartner-magic-quadrant-for-endpoint-protection-platforms/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft is named a Leader in the 2024 Gartner® Magic Quadrant™ for Endpoint Protection Platforms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2024/12/11/microsoft-defender-xdr-demonstrates-100-detection-coverage-across-all-cyberattack-stages-in-the-2024-mitre-attck-evaluations-enterprise/?msockid=3bef1be87261641b09e20845732c65d6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender XDR demonstrates 100% detection coverage across all cyberattack stages in the 2024 MITRE ATT&amp;amp;CK® Evaluations: Enterprise&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2023/10/23/forrester-names-microsoft-a-leader-in-the-2023-endpoint-security-wave-report/?msockid=1a665e69633567953e7a4b2062b1666a" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Forrester names Microsoft a Leader in the 2023 Endpoint Security Wave™ report&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"&gt;&lt;A href="https://www.av-comparatives.org/av-comparatives-awards-2024-for-microsoft/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;AV-Comparatives awards 2024 for Microsoft&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"&gt;&lt;A href="https://www.av-comparatives.org/vendors/microsoft/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AV-Comparatives antivirus tests &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;performed on Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To learn more about Microsoft Security solutions, visit our &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;website.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; Bookmark the &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) and X (&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;) for the latest news and updates on cybersecurity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;¹ &lt;/SPAN&gt;&lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Digital Defense Report 2024&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559737&amp;quot;:75,&amp;quot;335559738&amp;quot;:75,&amp;quot;335559739&amp;quot;:75}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 17:21:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-endpoint-successfully-passes-the-av-comparatives/ba-p/4414153</guid>
      <dc:creator>amibarayev</dc:creator>
      <dc:date>2025-05-15T17:21:19Z</dc:date>
    </item>
    <item>
      <title>Sensor Disconnection Notifications with Microsoft Defender for IoT and Microsoft Sentinel 🚀</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/sensor-disconnection-notifications-with-microsoft-defender-for/ba-p/4375517</link>
      <description>&lt;H3&gt;&lt;STRONG&gt;What Does This &lt;/STRONG&gt;&lt;STRONG&gt;Playbook&lt;/STRONG&gt;&lt;STRONG&gt; Do?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;This new &lt;STRONG&gt;automated playbook&lt;/STRONG&gt; sends real-time &lt;STRONG&gt;email notifications&lt;/STRONG&gt; whenever a sensor disconnects from the cloud. This ensures you’re immediately alerted if there’s an issue, allowing you to take quick action to investigate and resolve the problem.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Why It’s Important:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Real-Time Alerts:&lt;/STRONG&gt; Get instant notifications when a sensor goes offline.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Proactive Monitoring:&lt;/STRONG&gt; Identify the issue early, reducing downtime and improving response times.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Seamless Integration:&lt;/STRONG&gt; Works effortlessly with &lt;STRONG&gt;Microsoft Defender for IoT&lt;/STRONG&gt; and &lt;STRONG&gt;Microsoft Sentinel&lt;/STRONG&gt; for a unified security approach.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;How to Set It Up:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Setting up this playbook is quick and easy. For step-by-step instructions, check out the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/automate-sensor-disconnection-alerts" aria-label="Link detailed setup guide here" target="_blank"&gt;detailed setup guide here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This playbook was created in collaboration with Marian Hristov, a leading partner working with Defender for IoT.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 10:46:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/sensor-disconnection-notifications-with-microsoft-defender-for/ba-p/4375517</guid>
      <dc:creator>BelleKriger</dc:creator>
      <dc:date>2025-12-12T10:46:35Z</dc:date>
    </item>
  </channel>
</rss>

