Implementing Microsoft Defender Application Guard, Application Control, and exploit protection
Now that you know how to manage and monitor MDE, let’s take a look at some of its associated features, starting with Microsoft Defender Application Guard.
Configuring Microsoft Defender Application Guard
Microsoft Defender Application Guard is a system designed to isolate devices so that malicious actors are unable to use their attack methodologies against them. It protects your company’s users on Windows, specifically on the Microsoft Edge browser, by isolating untrusted sites when users browse the internet.
Microsoft Defender Application Guard empowers Microsoft 365 security administrators to explicitly define the following categories:
- Trusted websites
- Trusted cloud resources
- Trusted internal networks
A zero-trust methodology is employed to ensure that anything that is not defined in the preceding categories is considered untrusted and is blocked...