What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
Attack surface reduction (ASR) rules block risky software behaviours that malware commonly uses. The details that matter are rule modes, requirements, deployment methods and which exclusions apply.
ASR rules are a Microsoft Defender Antivirus feature for Windows. They target behaviour such as Office apps creating child processes, obfuscated scripts, code injection and credential theft from LSASS.
| Mode | Code | Behaviour |
|---|---|---|
| Off / Disabled | 0 | Explicitly disabled; can conflict with other policies |
| Block / Activated | 1 | Blocks the behaviour |
| Audit | 2 | Evaluates as if blocking, logs only (Windows events and Asr...Audited action types) |
| Not configured | 5 | Effectively off, without conflict potential |
| Warn | 6 | Blocks, but the user can select Unblock for 24 hours; Windows 10 1809 or later |
Warn isn’t supported by Block credential stealing from the Windows local security authority subsystem or Block Office applications from injecting code into other processes, and isn’t available in Configuration Manager. From platform 4.18.26060, using Unblock on a Warn-mode rule needs administrator approval.
Some rules depend on cloud protection (for example, the prevalence/age rule, obfuscated scripts and advanced ransomware protection). For several rules, EDR alerts appear only when the cloud protection level is High plus or Zero tolerance.
| Method | Notes |
|---|---|
| Intune endpoint security Attack surface reduction policy | Recommended; assign to device groups, not user groups |
| Defender portal endpoint security policies | Same policies as Intune (Windows platform, Attack surface reduction rules template) |
| Intune custom profile (OMA-URI) / any MDM via Policy CSP | ./Vendor/MSFT/Policy/Config/Defender/AttackSurfaceReductionRules, value GUID=mode |
| Configuration Manager | Microsoft Defender Antivirus policy in the Assets and compliance workspace; not every rule is supported |
| Group Policy | Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Attack Surface Reduction |
| PowerShell | Local only; supports all rules |
Precedence: local PowerShell settings are lowest and are overwritten at startup by policy. Group Policy wins over MDM by default unless MDMWinsOverGP is set to 1 through the Policy CSP. All methods except Intune endpoint security policies and Configuration Manager identify rules by GUID.
This PowerShell, run elevated, adds one rule in Audit mode without changing others; Set-MpPreference would overwrite the existing list.
Add-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions AuditModeAudit results can be reviewed in advanced hunting:
DeviceEvents
| where ActionType startswith "Asr"
| where ActionType endswith "Audited"
Common trap: Setting a rule to Disabled in one policy to turn it off while another policy enables it - Disabled can cause conflicts; Not configured is functionally off without conflict potential.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.