Skip to content

Commit 2ef90a9

Browse files
committed
Learn Editor: Update microsoft-defender-antivirus-using-powershell.md
1 parent 167c5c7 commit 2ef90a9

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

defender-endpoint/microsoft-defender-antivirus-using-powershell.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -126,6 +126,26 @@ Microsoft Defender Exploit Guard provides features that help protect devices fro
126126

127127
Some rules may block behavior you find acceptable in your organization. In these cases, change the rule from Enabled to Audit to prevent unwanted blocks.
128128

129+
#### Enable Tamper Protection
130+
131+
In the Microsoft XDR portal (security.microsoft.com), go to Settings > Endpoints > Advanced features > Tamper Protection > On.
132+
133+
For more information [How do I configure or manage tamper protection](/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection)
134+
135+
#### Check the Cloud Protection network connectivity
136+
137+
It is important to check that the Cloud Protection network connectivity is working during your pen testing.
138+
139+
CMD (Run as admin)
140+
141+
142+
```
143+
cd "C:\Program Files\Windows Defender"
144+
MpCmdRun.exe -ValidateMapsConnection
145+
```
146+
147+
For more information [Use the cmdline tool to validate cloud-delivered protection ](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus)
148+
129149
## One-click Microsoft Defender Offline Scan
130150

131151
Microsoft Defender Offline Scan is a specialized tool that comes with Windows 10 or newer, and allows you to boot a machine into a dedicated environment outside of the normal operating system. It's especially useful for potent malware, such as rootkits.

0 commit comments

Comments
 (0)