Defender Exploit Guard and Application Guard

Copper Contributor

Hi,

 

I would like to know general usage on the two of the Defender features.

  1. Exploit Guard
  2. Application Guard

These features are set to be mostly white list operation and it is difficult to have them enabled on all PCs in the company where each department uses different applications and web sites.

Since there is not enough case information available and is difficult to configure and maintain those features, I'd like to know if there is any case for deploying to company wide.

 

I appreciate for any information or cases.

 

It is best to provide case for only for those department with more security to be deployed in controlled manner and not recommending to deploy to company wide as the conclusion for me, but I lack on deployment cases to backup my suggestion to customer.

 

 

Hiroshi

 

 

1 Reply
Before you embark on the journey with Application Guard and Exploit Guard, compare the existing security controls the customer may have with their existing security tools. Overlap can cause issues with performance or stop the tools from working properly all together.

Generally, when employing any type of new security control, you will want to do a small test or pilot group for each department to know if it would benefit them. They may use certain applications, plugins, or features that would break when these rules are enforced. If during your test, you find it is beneficial and doesn't negatively impact the user, then expand from there.

Also keep in mind any type of Allow / Block type functionality usually requires a high amount of initial setup and maintenance, which may not be financially viable for the customer.

Exploit Guard is a more generalized protection feature that seeks to reduce the systems attack surface, and identify suspicious behavior. However, the settings may impact application functionality and compatibility if not properly configured. It's best to run the settings you want to try in Audit mode first, then see the results from there. You may find it works well, or that lots of customization will be needed.

More details here:
https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/create-deploy-exploit-guard-policy

Application Guard on the other hand creates a sandbox around certain applications and limits how data can move in and out the sandboxes. In my experience, I found this functionality didn't work well for many use cases just because of how users work. So for this, it would be best for you to run a test scenario. Start with one setting at a time, and understand if it limits anything, or makes sense to configure. Under the Microsoft Docs for Application Guard you can find details on how to setup a test scenario. Make sure the clients systems meet the minimum requirements as well!

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-application-g...

Hope this helps, and good luck!