Tamper protection
Tamper protection is a feature that, for the uninitiated, can be confusing. By itself, it is probably the best thing you can do to protect your environment against human-operated ransomware attacks where attackers like nothing more than to compromise your environment, then in one fell swoop disable Defender Antivirus and execute their ransomware payload. This feature shuts that down; it is very, very difficult to disable key components of Defender Antivirus without fully compromising the system to begin with, significantly raising the bar.
Originally, Defender Antivirus for Windows was designed with the end user, as a local administrator, in mind: you could choose to turn it off in various ways, even though the process itself is hardened using protected process light (PPL), an operating system capability that essentially requiring kernel-level permissions in order to stop the service. Tamper protection’s intent is to go beyond this and try to protect against...