Implementing and Managing Endpoint Protection by Using Microsoft Defender for Endpoint
Devices (especially those connected to the internet) are continuously under attack from malicious actors. These threat actors may attempt to compromise a device or system and use it either to gain access to an environment’s resources or for use as part of a larger system to attack other targets.
Whatever the scenario, Microsoft Defender for Endpoint (MDE) can be used to secure organizations against ransomware, file-less malware, credential compromise, and more advanced attacks.
MDE has several key features, including attack surface reduction (ASR), automatic investigation and remediation (AIR), and endpoint detection and response (EDR). These components, as well as next-generation virus detection and comprehensive threat management, are brought together as a comprehensive platform to protect Windows, macOS, iOS, Linux, and Android devices.
This chapter covers the following MS-102...