What's changed: Created SC-200 Chapter 1 (Domain 1 first-half: Defender XDR notifications/alert tuning (suppression)/correlation; Defender for Endpoint (advanced features/custom data collection/ASR rules/device groups/permissions/automation levels); AIR (automated investigation and response)/Action center/automatic attack disruption; Sentinel automation rules (declarative triage)/playbooks (Logic Apps, SOAR)).
1.2Configuring Defender for Endpoint and ASR
Understand Microsoft Defender for Endpoint advanced features, rule settings, custom data collection, security policies including attack surface reduction (ASR) rules, and device groups/permissions/automation levels.
Microsoft Defender for Endpoint (DfE) is the core of endpoint detection/response (EDR). The SOC analyst designs detection quality and the scope of automated response via policies and device groups.
1.2.1Advanced features and ASR rules
Enable DfE advanced features (automated investigation, live response, block/allow lists, etc.) and configure custom data collection needed for detection. Attack surface reduction (ASR) rules preventively block common attacker techniques (Office spawning child processes, obfuscated scripts, credential theft, etc.). Analysts roll out ASR in stages—"audit mode to assess impact → block mode to enforce"—to limit false positives.
1.2.2Device groups, permissions, and automation levels
Classify devices with device groups and vary permissions (RBAC) and automation levels per group. The automation level decides "auto-approve remediation vs wait for human approval"—e.g., critical servers semi-automated (await approval), general endpoints fully automated, by risk. This controls the scope of automated investigation and response (AIR, next section).
Cues: "preventively block ransomware-style techniques" = ASR rules (audit → block staged rollout). "vary permissions and auto-remediation scope per device" = device groups + automation levels. "critical servers await approval" = semi-automated; "general endpoints automatic" = fully automated.
Watch the mix-ups: (1) ASR rules (preventive block) differ from detection rules (detection). (2) Do not block ASR immediately—assess impact in audit mode first. (3) Automation level is per device group—set critical assets to await approval to limit damage from wrong remediation.
1.2.3Section summary
- Enable DfE advanced features/custom data collection; ASR rules preventively block common techniques (audit → block)
- Set permissions (RBAC) and automation level per device group (critical = semi-automated, general = fully automated)
- Automation level controls the auto-remediation scope of AIR
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to preventively block ransomware techniques (Office spawning child processes, credential theft). Which is best?
Q2. You want critical servers to await approval for remediation and general endpoints to be fully automatic. Which is best?
Q3. Before enforcing ASR rules, you want to assess business impact. What is the best approach?
Q4. Which is a primary purpose of device groups?
Q5. Which correctly distinguishes ASR rules from detection rules?

