What's changed: Created MS-102 Chapter 4 (domain: Defender XDR, part 2). Defender for Endpoint (onboarding script/Intune/GPO, endpoint settings ASR/EDR block mode/tamper protection, Defender Vulnerability Management surfacing/remediating) and Defender for Cloud Apps (Microsoft 365 app connector, activity/file policies for alerts, Cloud App Discovery for shadow IT and risk scores, activity log investigation).
4.1Defender for Endpoint
Understand onboarding devices to Microsoft Defender for Endpoint, endpoint settings (attack surface reduction ASR, EDR block mode, tamper protection), and Microsoft Defender Vulnerability Management for surfacing and remediating vulnerabilities.
Microsoft Defender for Endpoint provides device (endpoint) EDR/protection. Roll out in order: "connect (onboard)"→"configure (settings)"→"manage weaknesses".
4.1.1Onboarding devices
Onboarding connects devices to Defender for Endpoint, enabling telemetry and protection. Methods include a local onboarding script, Microsoft Intune, Group Policy (GPO), and Configuration Manager—choose by environment. Onboarding "registers a device as protected" and is the prerequisite for the settings and vulnerability management below.
4.1.2Endpoint settings
Endpoint settings harden protection. Attack surface reduction (ASR) rules block risky behaviors (e.g., Office macros spawning child processes); EDR in block mode blocks EDR-detected threats even when another AV is passive; tamper protection prevents malware/attackers from disabling security settings. These configure "how to defend an already-onboarded device."
4.1.3Vulnerability management
Microsoft Defender Vulnerability Management surfaces a device’s known vulnerabilities, misconfigurations, and recommendations on a dashboard, prioritizing remediation of high-risk items (security recommendations, software inventory, weaknesses). This is "continuously reducing weaknesses"—different in purpose from onboarding (connect) or endpoint settings (configure).
Cues: "connect a device as protected (script/Intune/GPO)" = onboarding. "harden with ASR/EDR block mode/tamper protection" = endpoint settings. "surface and remediate weaknesses on a dashboard" = Defender Vulnerability Management. Endpoint = device protection; Office 365 = email protection.
Watch the mix-ups: (1) Onboarding (connect) vs endpoint settings (configure) vs Vulnerability Management (weaknesses) are different steps. (2) Defender for Endpoint (device EDR) vs Defender for Office 365 (email/collab). (3) Tamper protection prevents disabling security settings—it is not vulnerability scanning.
4.1.4Section summary
- Onboarding connects devices to Defender for Endpoint (script/Intune/GPO)
- Endpoint settings = ASR/EDR block mode/tamper protection harden protection
- Defender Vulnerability Management surfaces vulnerabilities and prioritizes remediation
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to register a fleet of new Windows devices as protected by Microsoft Defender for Endpoint and enable telemetry. What is the first step?
Q2. You want to block risky behaviors like Office macros spawning child processes on devices to reduce attack surface. Best?
Q3. You want to prevent malware or attackers from disabling Defender security settings. Best?
Q4. You want a dashboard of devices’ known vulnerabilities/misconfigurations to remediate by risk. Best?
Q5. You want EDR protection for employees’ laptops (devices). Which product handles device protection, not email threat protection?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

