What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).
4.1Defender for Endpoint
Understand onboarding devices to Microsoft Defender for Endpoint, endpoint settings (attack surface reduction ASR, EDR block mode, tamper protection), and Microsoft Defender Vulnerability Management for surfacing and remediating vulnerabilities.
Microsoft Defender for Endpoint provides device (endpoint) EDR/protection. Roll out in order: "connect (onboard)"→"configure (settings)"→"manage weaknesses".
4.1.1Onboarding devices
Onboarding connects devices to Defender for Endpoint, enabling telemetry and protection. Methods include a local onboarding script, Microsoft Intune, Group Policy (GPO), and Configuration Manager—choose by environment. Onboarding "registers a device as protected" and is the prerequisite for the settings and vulnerability management below.
4.1.2Endpoint settings
Endpoint settings harden protection. Attack surface reduction (ASR) rules block risky behaviors (e.g., Office macros spawning child processes); EDR in block mode blocks EDR-detected threats even when another AV is passive; tamper protection prevents malware/attackers from disabling security settings. These configure "how to defend an already-onboarded device."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

