You manage Microsoft Defender Antivirus on 500 Azure AD–joined Windows 11 devices via Intune. To stop users from disabling Microsoft Defender for Endpoint, which action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: In the Microsoft 365 Defender portal, enable tamper protection.
Why this is the answer
Enabling tamper protection in the Microsoft 365 Defender portal is the correct action because it prevents users and malicious actors from disabling security features like Microsoft Defender Antivirus, even if they have administrative privileges on the device. This ensures the integrity of your endpoint security. Creating an attack surface reduction (ASR) policy helps prevent specific attack behaviors but does not stop users from disabling Defender itself. An account protection policy focuses on identity-related security like Windows Hello for Business and credential protection, not on preventing Defender from being turned off. A Conditional Access policy in Microsoft Entra (formerly Azure AD) controls access to resources based on conditions, but it doesn't manage device-level security settings like tamper protection for Defender.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed