Unblock Adobe Plug-in Blocked by ASR Policy
You have a Microsoft 365 E5 subscription. You use Microsoft Intune to manage all Windows 11 devices. You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile1 to all the devices. A user reports that an Adobe Reader plug-in is now blocked. You need to ensure that the plug-in is unblocked. What should you do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to remediate an ASR policy blocking a legitimate application by using per-rule exclusions, rather than changing unrelated policies.
When an Attack Surface Reduction (ASR) policy blocks a legitimate application plug-in, you must configure exclusions within the ASR profile. This page explains how to unblock the Adobe Reader plug-in by modifying the ASR policy exclusions.
Choosing Endpoint Privilege Management (A) or Device Compliance (D) because they sound like security or management policies, but they do not configure ASR rule exclusions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Configuring ASR Only Per Rule Exclusions in Profile1 allows an administrator to define specific processes, files, or folders that are exempt from the attack surface reduction rules. Since the Adobe Reader plug-in was blocked by Profile1, adding an exclusion for it directly resolves the issue without disabling the protection for the rest of the environment.Why the Other Options Are Wrong
Endpoint Privilege Management (A) is used to allow standard users to run applications that require elevated privileges, which does not address ASR rule blocking. Scope tags (B) are strictly for delegating administrative visibility via Role-Based Access Control (RBAC) and have no effect on policy enforcement or exclusions. A device compliance policy (D) evaluates device settings for compliance status but cannot override or exclude an endpoint security configuration like an ASR rule.Community Comment Notes
Commenters agreed that only option C makes sense in this context. As servL noted, "Endpoint Privilege Management policy enables users to run tasks requiring elevated privilege" and "Scope tags determine which objects admins can see," neither of which unblocks an ASR rule.Official Reference
Exam Strategy
When an Intune ASR policy blocks a legitimate application, look for the option that modifies exclusions within the ASR profile itself. Do not confuse privilege management or compliance policies with endpoint security rule exclusions.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →