You have a Microsoft 365 subscription with 500 Windows 11 computers that are Microsoft Entra joined and enrolled in Microsoft Intune. You will manage Microsoft Defender for Endpoint on these machines and must stop users from turning it off. What action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: In the Microsoft Defender portal, enable tamper protection..
Why this is the answer
Enabling tamper protection in the Microsoft Defender portal is the correct action because it prevents users and unauthorized processes from disabling or altering Microsoft Defender for Endpoint security features, including real-time protection and cloud-delivered protection. This ensures that the security solution remains active and effective on the Windows 11 devices. Creating an attack surface reduction (ASR) policy helps prevent malware by blocking suspicious behaviors but doesn't specifically stop users from disabling Defender. An account protection policy focuses on credential security and multi-factor authentication, not Defender's operational state. A device compliance policy assesses device health and configuration but doesn't directly enforce tamper protection for Defender.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed