Skip to content

Commit e0b9f52

Browse files
committed
Update attack-surface-reduction-rules-deployment-test.md
1 parent 6952b4d commit e0b9f52

File tree

1 file changed

+18
-12
lines changed

1 file changed

+18
-12
lines changed

defender-endpoint/attack-surface-reduction-rules-deployment-test.md

Lines changed: 18 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.collection:
1717
- highpri
1818
- tier1
1919
- mde-asr
20-
ms.date: 03/26/2025
20+
ms.date: 06/05/2025
2121
search.appverid: met150
2222
---
2323

@@ -56,33 +56,39 @@ Begin the testing phase by turning on the attack surface reduction rules with th
5656
You can use Microsoft Intune Endpoint Security to configure custom attack surface reduction rules.
5757

5858
1. Open the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
59+
5960
2. Go to **Endpoint Security** > **Attack surface reduction**.
61+
6062
3. Select **Create Policy**.
63+
6164
4. In **Platform**, select **Windows 10, Windows 11, and Windows Server**, and in **Profile**, select **Attack surface reduction rules**.
6265

63-
> [!div class="mx-imgBorder"]
64-
> :::image type="content" source="media/asr-mem-create-profile.png" alt-text="The profile creation page for ASR rules" lightbox="media/asr-mem-create-profile.png":::
66+
> [!div class="mx-imgBorder"]
67+
> :::image type="content" source="media/asr-mem-create-profile.png" alt-text="The profile creation page for ASR rules" lightbox="media/asr-mem-create-profile.png":::
6568
6669
5. Select **Create**.
70+
6771
6. In the **Basics** tab of the **Create profile** pane, in **Name** add a name for your policy. In **Description** add a description for your attack surface reduction rules policy.
72+
6873
7. In the **Configuration settings** tab, under **Attack Surface Reduction Rules**, set all rules to **Audit mode**.
6974

70-
> [!div class="mx-imgBorder"]
71-
> :::image type="content" source="media/asr-mem-configuration-settings.png" alt-text="The configuration of attack surface reduction rules to Audit mode" lightbox="media/asr-mem-configuration-settings.png":::
75+
> [!div class="mx-imgBorder"]
76+
> :::image type="content" source="media/asr-mem-configuration-settings.png" alt-text="The configuration of attack surface reduction rules to Audit mode" lightbox="media/asr-mem-configuration-settings.png":::
7277
73-
> [!NOTE]
74-
> There are variations in some attack surface reduction rules mode listings; _Blocked_ and _Enabled_ provide the same functionality.
78+
> [!NOTE]
79+
> There are variations in some attack surface reduction rules mode listings; _Blocked_ and _Enabled_ provide the same functionality.
7580
7681
8. [Optional] In the **Scope tags** pane, you can add tag information to specific devices. You can also use role-based access control and scope tags to make sure that the right admins have the right access and visibility to the right Intune objects. Learn more: [Use role-based access control (RBAC) and scope tags for distributed IT in Intune](/mem/intune/fundamentals/scope-tags).
77-
9. In the **Assignments** pane, you can deploy or "assign" the profile to your user or device groups. Learn more: [Assign device profiles in Microsoft Intune](/mem/intune/configuration/device-profile-assign#exclude-groups-from-a-profile-assignment)
7882

79-
> [!NOTE]
80-
> Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.
83+
9. In the **Assignments** pane, you can deploy or "assign" the profile to your user or device groups. For more information, see [Assign device profiles in Microsoft Intune](/mem/intune/configuration/device-profile-assign#exclude-groups-from-a-profile-assignment).
84+
85+
> [!NOTE]
86+
> Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.
8187
8288
10. Review your settings in the **Review + create** pane. Select **Create** to apply the rules.
8389

84-
> [!div class="mx-imgBorder"]
85-
> :::image type="content" source="media/asr-mem-review-create.png" alt-text="The Create profile page" lightbox="media/asr-mem-review-create.png":::
90+
> [!div class="mx-imgBorder"]
91+
> :::image type="content" source="media/asr-mem-review-create.png" alt-text="The Create profile page" lightbox="media/asr-mem-review-create.png":::
8692
8793
Your new attack surface reduction policy for attack surface reduction rules is listed in **Endpoint security | Attack surface reduction**.
8894

0 commit comments

Comments
 (0)