Instiq
Chapter 4 · Defender for Endpoint and Cloud Apps·v1.0.0·Updated 6/30/2026·~13 min

What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).

4.1Defender for Endpoint

Key points

Understand onboarding devices to Microsoft Defender for Endpoint, endpoint settings (attack surface reduction ASR, EDR block mode, tamper protection), and Microsoft Defender Vulnerability Management for surfacing and remediating vulnerabilities.

Microsoft Defender for Endpoint provides device (endpoint) EDR/protection. Roll out in order: "connect (onboard)"→"configure (settings)"→"manage weaknesses".

4.1.1Onboarding devices

Onboarding connects devices to Defender for Endpoint, enabling telemetry and protection. Methods include a local onboarding script, Microsoft Intune, Group Policy (GPO), and Configuration Manager—choose by environment. Onboarding "registers a device as protected" and is the prerequisite for the settings and vulnerability management below.

4.1.2Endpoint settings

Endpoint settings harden protection. Attack surface reduction (ASR) rules block risky behaviors (e.g., Office macros spawning child processes); EDR in block mode blocks EDR-detected threats even when another AV is passive; tamper protection prevents malware/attackers from disabling security settings. These configure "how to defend an already-onboarded device."

4.1.3Vulnerability management

Microsoft Defender Vulnerability Management surfaces a device’s known vulnerabilities, misconfigurations, and recommendations on a dashboard, prioritizing remediation of high-risk items (security recommendations, software inventory, weaknesses). This is "continuously reducing weaknesses"—different in purpose from onboarding (connect) or endpoint settings (configure).

Exam point

Cues: "connect a device as protected (script/Intune/GPO)" = onboarding. "harden with ASR/EDR block mode/tamper protection" = endpoint settings. "surface and remediate weaknesses on a dashboard" = Defender Vulnerability Management. Endpoint = device protection; Office 365 = email protection.

Warning

Watch the mix-ups: (1) Onboarding (connect) vs endpoint settings (configure) vs Vulnerability Management (weaknesses) are different steps. (2) Defender for Endpoint (device EDR) vs Defender for Office 365 (email/collab). (3) Tamper protection prevents disabling security settings—it is not vulnerability scanning.

Diagram: device (endpoint) EDR/protection. Connect = onboarding (script/Intune/GPO); configure = attack surface reduction (ASR) rules/EDR block mode/tamper protection; weakness management = Microsoft Defender Vulnerability Management surfaces a dashboard and prioritizes remediation; Endpoint is device protection, distinct from Office 365 email protection.
Connect→configure→weakness

4.1.4Section summary

  • Onboarding connects devices to Defender for Endpoint (script/Intune/GPO)
  • Endpoint settings = ASR/EDR block mode/tamper protection harden protection
  • Defender Vulnerability Management surfaces vulnerabilities and prioritizes remediation

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to register a fleet of new Windows devices as protected by Microsoft Defender for Endpoint and enable telemetry. What is the first step?

Q2. You want to block risky behaviors like Office macros spawning child processes on devices to reduce attack surface. Best?

Q3. You want to prevent malware or attackers from disabling Defender security settings. Best?

Q4. You want a dashboard of devices’ known vulnerabilities/misconfigurations to remediate by risk. Best?

Q5. You want EDR protection for employees’ laptops (devices). Which product handles device protection, not email threat protection?

Check your understandingPractice questions for Chapter 4: Defender for Endpoint and Cloud Apps

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.