Instiq
Chapter 3 · Protect devices·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created MD-102 Chapter 3 (domain: Protect devices). Endpoint security (antivirus/disk encryption BitLocker/firewall/Attack surface reduction/security baselines, Microsoft Defender for Endpoint integration EDR/onboard/threat investigation/incident triage, App Control for Business) and device updates (update rings, feature updates vs quality updates, Windows Autopatch, Hotpatch, Settings Catalog, Delivery Optimization, update monitoring).

3.1Endpoint security

Key points

Understand antivirus/disk encryption (BitLocker)/firewall/Attack surface reduction policies, security baselines, Microsoft Defender for Endpoint integration (EDR), and App Control for Business.

Endpoint security combines multiple policies; detection and response are handled by Microsoft Defender for Endpoint.

3.1.1Security policies

Intune antivirus policies configure Microsoft Defender Antivirus. Disk encryption policies encrypt disks with BitLocker, managing recovery keys, user self-service recovery, and encryption compliance. Firewall policies manage the firewall; Attack surface reduction (ASR) policies block risky behaviors (Zero Trust). Security baselines are templates applying Microsoft’s recommended bundle of security settings. Distinguish "anti-malware" = antivirus from "behavior blocking" = ASR from "bundle of settings" = security baseline.

3.1.2Defender for Endpoint and App Control

Integrate Microsoft Defender for Endpoint with Intune to deploy EDR (Endpoint Detection and Response) policies, onboard devices, investigate threats, and triage incidents (the core of detection/response). App Control for Business allows only approved apps to run, preventing unsanctioned/malicious app execution. Whereas antivirus/ASR/baselines are "preventive configuration," Defender for Endpoint’s role is "detection and response."

Exam point

Cues: "configure anti-malware (Defender Antivirus)" = antivirus policy. "encrypt disks with BitLocker, manage recovery keys" = disk encryption policy. "block risky behaviors" = Attack surface reduction (ASR). "apply a recommended settings bundle" = security baseline. "detect/investigate threats, incident response (EDR)" = Microsoft Defender for Endpoint. "allow only approved apps to run" = App Control for Business.

Warning

Watch the mix-ups: (1) Antivirus (anti-malware) vs ASR (behavior blocking) vs security baseline (settings bundle). (2) Disk encryption = BitLocker encryption and recovery key management. (3) Defender for Endpoint (detection/response EDR) is a different layer from preventive policies. (4) App Control for Business is allowlist-based app execution control.

Diagram: antivirus policy detects/removes malware; attack surface reduction (ASR) blocks risky behaviors with rules; a security baseline applies a bundle of recommended settings (distinct roles); disk encryption (BitLocker) encrypts disks and manages recovery keys (self-service recovery lets users retrieve them); Microsoft Defender for Endpoint integration gives EDR/incident triage; App Control for Business allows only approved apps (allowlist); a firewall policy controls traffic.
Roles of protection policies

3.1.3Section summary

  • Antivirus/firewall/ASR/disk encryption (BitLocker)/security baselines protect preventively
  • Defender for Endpoint integration for EDR, onboard, threat investigation, incident response
  • App Control for Business allows only approved apps to run

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to encrypt Intune-managed Windows device disks with BitLocker and manage recovery keys. Best?

Q2. You want to block risky behaviors like Office macros spawning child processes on devices. Best?

Q3. You want to apply many Microsoft-recommended security settings as a template at once. Best?

Q4. You want to detect/investigate device threats and triage/respond as incidents. Which product integrates with Intune?

Q5. You want only approved apps to run and prevent unsanctioned app execution. Best?

Check your understandingPractice questions for Chapter 3: Protect devices