Skip to content

Commit 2d18702

Browse files
committed
Update enable-attack-surface-reduction.md
1 parent 3408ee6 commit 2d18702

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

defender-endpoint/enable-attack-surface-reduction.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
- mde-asr
1616
ms.custom: admindeeplinkDEFENDER
1717
search.appverid: met150
18-
ms.date: 05/08/2025
18+
ms.date: 06/05/2025
1919
---
2020

2121
# Enable attack surface reduction rules
@@ -54,7 +54,7 @@ You can set attack surface reduction rules for devices that are running any of t
5454

5555
To use the entire feature-set of attack surface reduction rules, you need:
5656

57-
- Microsoft Defender Antivirus as primary antivirus Note: Microsoft Defender Antivirus cannot be running in "Passive Mode" or "Disabled"
57+
- Microsoft Defender Antivirus as primary antivirus. Microsoft Defender Antivirus can't be running in passive mode or be disabled.
5858

5959
- [Real-time protection](/defender-endpoint/configure-real-time-protection-microsoft-defender-antivirus) to be on
6060

@@ -65,13 +65,13 @@ To use the entire feature-set of attack surface reduction rules, you need:
6565
- Microsoft 365 E5 or E3 License
6666

6767
> [!IMPORTANT]
68-
> The pre-requisites above are necessary in order for Attack Surface Reduction rules to work properly.
68+
> The prerequisites listed in this article are necessary in order for Attack Surface Reduction rules to work properly.
6969
7070
Although attack surface reduction rules don't require a [Microsoft 365 E5 license](/microsoft-365/commerce/licenses/e3-extra-features-licenses), with Microsoft 365 E5 license, you get advanced management capabilities including monitoring, analytics, and workflows available in Defender for Endpoint, as well as reporting and configuration capabilities in the [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) portal. These advanced capabilities aren't available with an E3 license, but you can still use Event Viewer to review attack surface reduction rule events.
7171

7272
Each attack surface reduction rule contains one of four settings:
7373

74-
- **Not configured** | **Disabled**: Disable the attack surface reduction rule
74+
- **Not configured** or **Disabled**: Disable the attack surface reduction rule
7575
- **Block**: Enable the attack surface reduction rule
7676
- **Audit**: Evaluate how the attack surface reduction rule would impact your organization if enabled
7777
- **Warn**: Enable the attack surface reduction rule but allow the end user to bypass the block

0 commit comments

Comments
 (0)