Skip to content

Commit 187aa9a

Browse files
authored
Merge pull request #4577 from YongRhee-MSFT/docs-editor/attack-surface-reduction-rules-1753485272
Update attack-surface-reduction-rules-reference.md
2 parents def4f38 + bacddb0 commit 187aa9a

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-endpoint/attack-surface-reduction-rules-reference.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -406,8 +406,8 @@ This rule blocks executable files, such as .exe, .dll, or .scr, from launching.
406406

407407
> [!IMPORTANT]
408408
> You must [enable cloud-delivered protection](/windows/security/threat-protection/microsoft-defender-antivirus/enable-cloud-protection-microsoft-defender-antivirus) to use this rule.
409-
> The rule **Block executable files from running unless they meet a prevalence, age, or trusted list criterion** with GUID `01443614-cd74-433a-b99e-2ecdc07bfc25` is owned by Microsoft and isn't specified by admins. This rule uses cloud-delivered protection to update its trusted list regularly.
410-
> You can specify individual files or folders (using folder paths or fully qualified resource names) but you can't specify which rules or exclusions apply to.
409+
> This rule uses cloud-delivered protection to update its trusted list regularly.
410+
> You can specify individual files or folders by using folder paths or fully qualified resource names. It also supports the **ASROnlyPerRuleExclusions** setting.
411411
412412
Intune name: `Executables that don't meet a prevalence, age, or trusted list criteria`
413413

0 commit comments

Comments
 (0)