Skip to content

Commit d1e8b99

Browse files
committed
Add asr rules
1 parent 4aa9f93 commit d1e8b99

10 files changed

Lines changed: 24 additions & 17 deletions

memdocs/intune/fundamentals/whats-new.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: Erikre
88
ms.author: erikre
99
manager: dougeby
10-
ms.date: 04/04/2022
10+
ms.date: 04/05/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: fundamentals
@@ -83,7 +83,6 @@ The following profile templates are now available in the new settings format:
8383
| Antivirus | Windows 10, Windows 11, and Windows Server | Windows Security experience |
8484
| Antivirus | Windows 10, Windows 11, and Windows Server | Windows Defender Antivirus |
8585
| Antivirus | Windows 10, Windows 11, and Windows Server | Windows Defender Antivirus Exclusions
86-
| Disk Encryption | Windows 10 and Later | BitLocker |
8786
| Firewall | Windows 10, Windows 11, and Windows Server | Microsoft Defender Firewall |
8887
| Firewall | Windows 10, Windows 11, and Windows Server | Microsoft Defender Firewall Rules |
8988
| Endpoint detection and response | Windows 10, Windows 11, and Windows Server | Endpoint detection and response |

memdocs/intune/protect/antivirus-microsoft-defender-settings-windows.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ ms.reviewer: laarrizz
3131
# Settings for Microsoft Defender Antivirus policy in Microsoft Intune for Windows devices
3232

3333
> [!NOTE]
34-
> This article details the settings in the Microsoft Defender Antivirus and Microsoft Defender Antivirus Exclusions profiles for the *Windows 10 and later* platform for endpoint security Antivirus policy. Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details in this article apply to those deprecated profiles.
34+
> This article details the settings in the Microsoft Defender Antivirus and Microsoft Defender Antivirus Exclusions profiles for the *Windows 10 and later* platform for endpoint security Antivirus policy. Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details in this article apply to those deprecated profiles.
3535
3636
View details about the [endpoint security](../protect/endpoint-security-policy.md) antivirus policy settings you can configure for the Microsoft Defender Antivirus profile for Windows 10 and later in Microsoft Intune.
3737

memdocs/intune/protect/antivirus-security-experience-windows-settings.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ ms.reviewer: mattsha
3131
# Settings for the Windows Security experience profile in Microsoft Intune
3232

3333
> [!NOTE]
34-
> This article details the settings in the Windows Security experience profile for the *Windows 10 and later* platform for endpoint security Antivirus policy. Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles.
34+
> This article details the settings in the Windows Security experience profile for the *Windows 10 and later* platform for endpoint security Antivirus policy. Beginning on April, 5 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles.
3535
3636
View details about the [endpoint security](../protect/endpoint-security-policy.md) antivirus policy settings you can configure for the Windows Security Experience profile for Windows 10 and later in Microsoft Intune.
3737

memdocs/intune/protect/endpoint-security-antivirus-policy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,7 @@ Profiles for *Antivirus* policy that support tamper protection for [devices mana
8080
- Profile: **Windows Security experience**
8181

8282
> [!NOTE]
83-
> Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
83+
> Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
8484
>
8585
> The *Windows 10, Windows 11, and Windows Server* platform supports devices communicating with Endpoint Manager through Microsoft Intune or Microsoft Defender for Endpoint. These profiles also add support for the Windows Server platform which is not supported through Microsoft Intune natively.
8686
>
@@ -118,7 +118,7 @@ The following profiles are supported for devices you manage with Intune:
118118
**Windows**:
119119

120120
> [!NOTE]
121-
> Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
121+
> Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
122122
>
123123
> The *Windows 10, Windows 11, and Windows Server* platform supports devices communicating with Endpoint Manager through Microsoft Intune or Microsoft Defender for Endpoint. These profiles also add support for the Windows Server platform which is not supported through Microsoft Intune natively.
124124
>

memdocs/intune/protect/endpoint-security-asr-policy.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,13 @@ Find the endpoint security policies for attack surface reduction under *Manage*
5353

5454
## Attack surface reduction profiles
5555

56+
> [!NOTE]
57+
> Beginning on April 5, 2022, the following profiles for Attack surface reduction policy have been updated to use the settings format as found in the Settings Catalog, while the other profiles are unchanged:
58+
> - Attack surface reduction rules
59+
> - Exploit protection
60+
> The new versions of these two profiles include the same settings as the older profile templates they replace. With this change, all new instances of these profiles will use the new settings format. Your previously crated instances of these profiles remain available to use and edit.
61+
62+
5663
### Devices managed by Intune
5764

5865
**Windows 10/11 profiles**:
@@ -83,7 +90,6 @@ Find the endpoint security policies for attack surface reduction under *Manage*
8390
- Behaviors that apps don't usually start during normal day-to-day work
8491
Reducing your attack surface means offering attackers fewer ways to perform attacks.
8592

86-
To learn more, see [Attack surface reduction rules](/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction) in the Microsoft Defender for Endpoint documentation.
8793

8894
**Merge behavior for Attack surface reduction rules in Intune**:
8995

@@ -106,8 +112,6 @@ Reducing your attack surface means offering attackers fewer ways to perform atta
106112

107113
- **Exploit protection** - Exploit protection settings can help protect against malware that uses exploits to infect devices and spread. Exploit protection consists of a number of mitigations that can be applied to either the operating system or individual apps.
108114

109-
To learn more, see [Enable exploit protection](/windows/security/threat-protection/microsoft-defender-atp/enable-exploit-protection) in the Microsoft Defender for Endpoint documentation.
110-
111115
### Devices managed by Configuration Manager
112116

113117
[!INCLUDE [Attack surface reduction prerequisites](../includes/tenant-attach-asr-prerequisites.md)]
@@ -150,6 +154,4 @@ Policy merge doesn’t compare or merge the configurations from different settin
150154

151155
[Configure Endpoint security policies](../protect/endpoint-security-policy.md#create-an-endpoint-security-policy)
152156

153-
View details for the Windows settings in the deprecated profiles:
154-
155-
- [Attack surface reduction profiles](../protect/endpoint-security-asr-profile-settings.md).
157+
View details for the settings in profiles for [Attack surface reduction profiles](../protect/endpoint-security-asr-profile-settings.md).

memdocs/intune/protect/endpoint-security-asr-profile-settings.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 11/01/2021
10+
ms.date: 04/04/2022
1111
ms.topic: reference
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -211,6 +211,9 @@ Supported platforms and profiles:
211211

212212
#### Attack Surface Reduction Rules
213213

214+
> [!NOTE]
215+
> This section details the settings in Attack Surface Reduction Rules profiles created before April 5, 2022. Profiles created after that date use a new settings format as found in the Settings Catalog. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles.
216+
214217
- **Block persistence through WMI event subscription**
215218
[Reduce attack surfaces with attack surface reduction rules](/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction)
216219

@@ -543,6 +546,9 @@ Supported platforms and profiles:
543546

544547
#### Exploit protection
545548

549+
> [!NOTE]
550+
> This section details the settings you can find in Exploit protection profiles created before April 5, 2022. Profiles created after that date use a new settings format as found in the Settings Catalog. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles.
551+
546552
- **Upload XML**
547553
CSP: [ExploitProtectionSettings](/windows/client-management/mdm/policy-csp-exploitguard#exploitguard-exploitprotectionsettings)
548554

memdocs/intune/protect/endpoint-security-edr-policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@ Find the endpoint security policies for EDR under *Manage* in the **Endpoint sec
6565
**Intune** – The following are supported for devices you manage with Intune:
6666

6767
> [!NOTE]
68-
> Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
68+
> Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
6969
>
7070
> The *Windows 10, Windows 11, and Windows Server* platform supports devices communicating with Endpoint Manager through Microsoft Intune or Microsoft Defender for Endpoint. These profiles also add support for the Windows Server platform which is not supported through Microsoft Intune natively.
7171
>

memdocs/intune/protect/endpoint-security-edr-profile-settings.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ ms.reviewer: mattcall
3030
# Endpoint detection and response policy settings for endpoint security in Intune
3131

3232
> [!NOTE]
33-
> This article details the settings in the Endpoint detection and response profile for the *Windows 10 and later* platform for endpoint security Endpoint detection and response policy. Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details in this article apply to those deprecated profiles.
33+
> This article details the settings in the Endpoint detection and response profile for the *Windows 10 and later* platform for endpoint security Endpoint detection and response policy. Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details in this article apply to those deprecated profiles.
3434
3535
View the settings you can configure in profiles for [Endpoint detection and response policy](../protect/endpoint-security-edr-policy.md) in the endpoint security node of Intune.
3636

memdocs/intune/protect/endpoint-security-firewall-policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ Find the endpoint security policies for firewalls under *Manage* in the **Endpoi
5454
**Platform: Windows 10, Windows 11, and Windows Server**:
5555

5656
> [!NOTE]
57-
> Beginning in April 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
57+
> Beginning on April 5, 2022, the *Windows 10 and later* platform was replaced by the *Windows 10, Windows 11, and Windows Server* platform.
5858
>
5959
> The *Windows 10, Windows 11, and Windows Server* platform supports devices communicating with Endpoint Manager through Microsoft Intune or Microsoft Defender for Endpoint. These profiles also add support for the Windows Server platform which is not supported through Microsoft Intune natively.
6060
>

memdocs/intune/protect/endpoint-security-firewall-profile-settings.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ ms.reviewer: aanavath
3030
# Firewall policy settings for endpoint security in Intune
3131

3232
> [!NOTE]
33-
> Beginning in April 2022, the *Windows 10 and later* platform and profiles for Windows devices were replaced by the *Windows 10, Windows 11, and Windows Server* platform and new instances of those same profiles. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details for Windows profiles in this article apply to those deprecated profiles.
33+
> Beginning on April 5, 2022, the *Windows 10 and later* platform and profiles for Windows devices were replaced by the *Windows 10, Windows 11, and Windows Server* platform and new instances of those same profiles. Although you can no longer create new instances of the original profile, you can continue to edit and use your existing profiles. The settings details for Windows profiles in this article apply to those deprecated profiles.
3434
3535
View the settings you can configure in profiles for *Firewall* policy in the endpoint security node of Intune as part of an [Endpoint security policy](../protect/endpoint-security-policy.md).
3636

0 commit comments

Comments
 (0)