Skip to content

Commit 890c1f3

Browse files
committed
Update enable-attack-surface-reduction.md
1 parent 2cb176b commit 890c1f3

File tree

1 file changed

+7
-2
lines changed

1 file changed

+7
-2
lines changed

defender-endpoint/enable-attack-surface-reduction.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -292,12 +292,17 @@ Example:
292292
> There is a known issue with the applicability of attack surface reduction on Server OS versions which is marked as compliant without any actual enforcement. Currently, there is no defined release date for when this will be fixed.
293293
294294
> [!NOTE]
295-
> If you're using Disable admin merge with Microsoft Defender for Endpoint Security Settings Management (Disable Local Admin Merge) or Microsoft Intune (Disable Local Admin Merge) or CSP (**[DisableLocalAdminMerge](/windows/client-management/mdm/defender-csp)**) or Group Policy (Configure local administrator merge behavior for lists) to `true` on devices, adding ASR rules per rule exclusions and ASR rules exclusions locally, they will not apply. To modify the behavior, you will need to change it to false.
295+
> If you're using "Disable admin merge" set to `true` on devices, and you're using any of the following tools/methods, adding ASR rules per-rule exclusions or local ASR rule exclusions don't apply.
296+
> - Defender for Endpoint Security Settings Management (Disable Local Admin Merge)
297+
> - Intune (Disable Local Admin Merge)
298+
> - The Defender CSP (**[DisableLocalAdminMerge](/windows/client-management/mdm/defender-csp)**)
299+
> - Group Policy (Configure local administrator merge behavior for lists)
300+
> To modify this behavior, you need to change "Disable admin merge" to `false`.
296301
297302
### Group policy
298303

299304
> [!WARNING]
300-
> If you manage your computers and devices with Intune, Configuration Manager, or other enterprise-level management platform, the management software will overwrite any conflicting group policy settings on startup.
305+
> If you manage your computers and devices with Intune, Configuration Manager, or other enterprise-level management platform, the management software overwrites any conflicting group policy settings on startup.
301306
302307
1. On your Group Policy management computer, open the [Group Policy Management Console](https://technet.microsoft.com/library/cc731212.aspx), right-click the Group Policy Object you want to configure and select **Edit**.
303308

0 commit comments

Comments
 (0)