Settings for things like the firewall, EDR, antivirus and ASR rules, defined in either Intune or the Defender portal. Defender for Endpoint security settings management is what delivers them to machines.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Endpoint security policies in context, with comparison tables and the common traps.
Terms in this definition
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- EDR
Defender for Endpoint's endpoint detection and response, which uses behaviour to detect and react to post-breach activity and continues even when Defender Antivirus is passive.
- Attack surface reduction
Protections in Defender for Endpoint that close off behaviour attackers like to abuse. Chief among them are ASR rules, which on Windows can stop Office programs spawning child processes or obfuscated scripts from running.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Defender for Endpoint security settings management
Lets devices that are not Intune-enrolled, but are onboarded to Defender for Endpoint, still receive Intune endpoint security policies. Assignment filters are ignored for these devices, which check in every 90 minutes.