FREE STUDY NOTES · SC-200

Attack surface reduction rules: requirements, modes, deployment and exclusions

What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Attack surface reduction (ASR) rules block risky software behaviours that malware commonly uses. The details that matter are rule modes, requirements, deployment methods and which exclusions apply.

ASR rules are a Microsoft Defender Antivirus feature for Windows. They target behaviour such as Office apps creating child processes, obfuscated scripts, code injection and credential theft from LSASS.

Requirements

Modes

Mode Code Behaviour
Off / Disabled 0 Explicitly disabled; can conflict with other policies
Block / Activated 1 Blocks the behaviour
Audit 2 Evaluates as if blocking, logs only (Windows events and Asr...Audited action types)
Not configured 5 Effectively off, without conflict potential
Warn 6 Blocks, but the user can select Unblock for 24 hours; Windows 10 1809 or later

Warn isn’t supported by Block credential stealing from the Windows local security authority subsystem or Block Office applications from injecting code into other processes, and isn’t available in Configuration Manager. From platform 4.18.26060, using Unblock on a Warn-mode rule needs administrator approval.

Rule categories

Some rules depend on cloud protection (for example, the prevalence/age rule, obfuscated scripts and advanced ransomware protection). For several rules, EDR alerts appear only when the cloud protection level is High plus or Zero tolerance.

Deploying rules

Method Notes
Intune endpoint security Attack surface reduction policy Recommended; assign to device groups, not user groups
Defender portal endpoint security policies Same policies as Intune (Windows platform, Attack surface reduction rules template)
Intune custom profile (OMA-URI) / any MDM via Policy CSP ./Vendor/MSFT/Policy/Config/Defender/AttackSurfaceReductionRules, value GUID=mode
Configuration Manager Microsoft Defender Antivirus policy in the Assets and compliance workspace; not every rule is supported
Group Policy Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Attack Surface Reduction
PowerShell Local only; supports all rules

Precedence: local PowerShell settings are lowest and are overwritten at startup by policy. Group Policy wins over MDM by default unless MDMWinsOverGP is set to 1 through the Policy CSP. All methods except Intune endpoint security policies and Configuration Manager identify rules by GUID.

This PowerShell, run elevated, adds one rule in Audit mode without changing others; Set-MpPreference would overwrite the existing list.

Add-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions AuditMode

Audit results can be reviewed in advanced hunting:

DeviceEvents
| where ActionType startswith "Asr"
| where ActionType endswith "Audited"

Exclusions

Common trap: Setting a rule to Disabled in one policy to turn it off while another policy enables it - Disabled can cause conflicts; Not configured is functionally off without conflict potential.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes