Microsoft Defender for Endpoint (MDE) is the endpoint detection and response (EDR) and protection product in Defender XDR. It uses sensors built into Windows and agents for macOS, Linux, iOS and Android to send telemetry to the cloud, where detections become alerts. It also manages Microsoft Defender Antivirus and a set of hardening features. Configuring it well decides whether your SOC sees attacks at all and whether common attack techniques are blocked before they start.
Onboarding connects a device to your tenant. Methods include a local script (good for a handful of test machines), Group Policy, Microsoft Intune, Configuration Manager, scripts for non-persistent virtual desktops, and Defender for Cloud for servers. Each method uses an onboarding package downloaded from Settings, Endpoints, Onboarding, where you pick the operating system and deployment method. After onboarding, the same page offers a harmless detection test command that produces a test alert, which is how you confirm the device reports. You can also check the device's health state and last-seen time in the device inventory. Offboarding uses a separate package and is how you retire a device cleanly. Device discovery uses onboarded devices to find unmanaged devices on the same networks. Standard discovery, the default, actively probes found devices to learn more about them; basic discovery only listens passively to traffic the onboarded device already sees. Discovered devices appear in the device inventory with an onboarding status such as can be onboarded or unsupported, so you can close gaps attackers love.
Device groups, covered in the previous lesson, control who can see and act on each device and the automated remediation level it gets. Tamper protection stops people, including local administrators and malware running with admin rights, from turning off real-time protection, cloud-delivered protection, behavior monitoring and other security settings. Attackers commonly try to disable antivirus before running ransomware, so tamper protection should be on everywhere. You turn it on tenant-wide under Settings, Endpoints, Advanced features, or manage it per device through Intune, and changes made locally, for example with Set-MpPreference -DisableRealtimeMonitoring $true, are then ignored.
Attack surface reduction (ASR) rules block behaviors that attackers use and normal users rarely need: Office apps creating child processes, credential stealing from the Local Security Authority Subsystem Service (LSASS), obfuscated scripts, executable content from email and others. Each rule has a mode. Audit logs what would have been blocked without blocking it. Warn blocks but lets the user click through, and not every rule supports it. Block enforces the rule. The safe rollout is audit first, review the events in the ASR report or in advanced hunting, add narrow exclusions for legitimate line-of-business apps, then move to block in stages. Intune's endpoint security profiles are the usual place to set modes, and a quick hunting query looks like DeviceEvents | where ActionType startswith "Asr".
Indicators of compromise (IoCs) are your own allow or block entries, created under Settings, Endpoints, Indicators. File hash indicators can allow, audit, warn, block execution or block and remediate. IP address, URL and domain indicators and certificate indicators work similarly and can be scoped to device groups. For IP and URL indicators to block traffic from browsers other than Microsoft Edge and from other processes, network protection must be turned on in block mode, and the custom network indicators advanced feature must be enabled. Network protection extends SmartScreen-style reputation blocking to the whole operating system, so it also stops connections to known malicious or command-and-control sites. Like ASR, it has an audit mode for testing.
Consider a worked example. An accounting firm wants to block Office macros from launching child processes. The admin sets that ASR rule to audit for two weeks, finds that a reporting add-in triggers it, adds a path exclusion for that add-in, then switches the rule to block for a pilot device group before rolling it out everywhere. Meanwhile device discovery shows three unmanaged laptops, which are onboarded through Intune.
Common mistakes: jumping straight to block and breaking business apps; creating a URL block indicator and wondering why Chrome ignores it (network protection is off); turning tamper protection on through Intune for some devices but leaving others unmanaged; assuming audit mode protects anything (it only logs); using a broad folder exclusion that attackers can abuse; and thinking device discovery onboards devices automatically. It only finds them.
Exam wording is usually direct. 'Test the impact of a rule without affecting users' means audit mode. 'Let users bypass with a warning' means warn mode. 'A local administrator or malware disabled antivirus' means tamper protection. 'Block a malicious domain for all browsers and processes' means an indicator plus network protection in block mode. 'Find devices that are not onboarded' means device discovery and the device inventory. 'Confirm onboarding works' means the detection test.
Key terms
- Onboarding package
- The script or configuration downloaded from the Defender portal that connects a device to your tenant through a chosen deployment method.
- Tamper protection
- A setting that prevents local changes to Defender security settings, even by administrators or malware with admin rights.
- ASR rule modes
- Audit logs only, Warn blocks but allows a user bypass, and Block enforces the rule.
- Indicator
- A custom allow, audit, warn or block entry for a file hash, IP address, URL, domain or certificate.
- Network protection
- An operating-system-wide filter that blocks connections to malicious domains and IPs and enforces custom IP and URL indicators outside Edge.
- Device discovery
- The feature that uses onboarded devices to find unmanaged devices on the network, in basic (passive) or standard (active) mode.
An accounting firm wants to block Office macros from launching child processes. The admin sets that ASR rule to audit for two weeks, finds that a reporting add-in triggers it, adds an exclusion for that add-in's path, then switches the rule to block for a pilot group before rolling it out to all device groups. The same week, device discovery finds three unmanaged laptops, which the team onboards through Intune.
Check yourself
A custom URL block indicator works in Edge but not in Chrome. What is missing?
Network protection in block mode (with custom network indicators enabled). It enforces IP and URL indicators for other browsers and processes.
What does warn mode do in an ASR rule?
It blocks the action but shows the user a notice that lets them unblock it and continue, for rules that support warn.
How can you find devices on your network that are not onboarded to Defender for Endpoint?
Use device discovery; the unmanaged devices it finds appear in the device inventory for onboarding.
How do you confirm a newly onboarded device is reporting?
Run the detection test command from the onboarding page and check that a test alert appears and the device shows in the inventory.