Overview of Microsoft Defender for Endpoint
Before we dive into configuration and planning topics, it’s important to understand the features and requirements associated with MDE.
Tip
This chapter features a lot of hands-on exercises and demonstrations. The best way to experience these features is to follow along as much as possible with trial subscriptions to the Microsoft 365 Defender suite.
Features
As mentioned earlier, MDE is a collection of several related security features:
- Attack surface reduction (ASR): This advanced feature is used to limit the potential attack vectors on a particular device. ASR includes concepts such as controlled folder access, code integrity audits, preventing child processes from spawning, and blocking executable content from executing.
Further Reading
For a detailed list of all of the ASR rules and platform capabilities, see https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface...