Skip to content

Commit 7408c0e

Browse files
committed
Update mde-p1-setup-configuration.md
1 parent 2a2cc45 commit 7408c0e

File tree

1 file changed

+8
-12
lines changed

1 file changed

+8
-12
lines changed

defender-endpoint/mde-p1-setup-configuration.md

Lines changed: 8 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -214,24 +214,20 @@ We recommend using Intune to configure controlled folder access.
214214

215215
1. Go to the [Intune admin center](https://intune.microsoft.com) and sign in.
216216

217-
2. Select **Endpoint Security**, and then select **Attack Surface Reduction**.
217+
2. Go to **Endpoint Security** > **Attack Surface Reduction**, and then choose **+ Create Policy**.
218218

219-
3. Choose **+ Create Policy**.
219+
3. For **Platform**, select **Windows 10, Windows 11, and Windows Server**, and for **Profile**, select **Attack surface reduction rules**. Then choose **Create**.
220220

221-
4. For **Platform**, select **Windows 10, Windows 11, and Windows Server**, and for **Profile**, select **Attack surface reduction rules**. Then choose **Create**.
222-
223-
5. On the **Basics** tab, name the policy and add a description. Select **Next**.
221+
4. On the **Basics** tab, name the policy and add a description. Select **Next**.
224222

225-
6. On the **Configuration settings** tab, in the **Attack Surface Reduction Rules** section, scroll down to the bottom. In the **Enable Controlled Folder Access** drop-down, select **Enable**. You can optionally specify these other settings:
223+
5. On the **Configuration settings** tab, under **Defender** section, scroll down to the bottom. In the **Enable Controlled Folder Access** drop-down, select **Enabled**, and then choose **Next**.
226224

227-
- Next to **Controlled Folder Access Protected Folders**, toggle the switch to **Configured**, and then add folders that need to be protected.
228-
- Next to **Controlled Folder Access Allowed Applications**, toggle the switch to **Configured**, and then add apps that should have access to protected folders.
225+
You can optionally specify these other settings:
229226

230-
Then choose **Next**.
227+
- Next to **Controlled Folder Access Protected Folders**, toggle the switch to **Configured**, and then add folders that need to be protected.
228+
- Next to **Controlled Folder Access Allowed Applications**, toggle the switch to **Configured**, and then add apps that should have access to protected folders.
231229

232-
7. On the **Scope tags** tab, if your organization is using scope tags, choose **+ Select scope tags**, and then select the tags you want to use. Then, choose **Next**.
233-
234-
To learn more about scope tags, see [Use role-based access control (RBAC) and scope tags for distributed IT](/mem/intune/fundamentals/scope-tags).
230+
7. On the **Scope tags** tab, if your organization is using scope tags, choose **+ Select scope tags**, and then select the tags you want to use. Then, choose **Next**. To learn more about scope tags, see [Use role-based access control (RBAC) and scope tags for distributed IT](/mem/intune/fundamentals/scope-tags).
235231

236232
8. On the **Assignments** tab, select **Add all users** and **+ Add all devices**, and then choose **Next**. (You can alternately specify specific groups of users or devices.)
237233

0 commit comments

Comments
 (0)