Your Microsoft 365 subscription contains 500 Windows 11 computers that are Azure AD joined and enrolled in Intune. You need to prevent users from disabling Microsoft Defender Antivirus. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: In the Microsoft 365 Defender portal, enable tamper protection.
Why this is the answer
Enabling tamper protection in the Microsoft 365 Defender portal is the correct solution. Tamper protection prevents malicious apps and users from disabling, changing, or deleting security features like Microsoft Defender Antivirus settings. This ensures that Defender Antivirus remains active and cannot be turned off by users on the Windows 11 devices. Creating a security baseline in Intune is too broad; while it can configure Defender settings, it doesn't specifically prevent users from disabling it. An account protection policy focuses on identity-related threats, not direct manipulation of antivirus settings. An EDR policy is for detecting and responding to advanced threats, not for preventing users from disabling core security features.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed