Unblock Adobe Plug-in Blocked by ASR Policy

Configure endpoint security
Answer Correct answer: C — Configure ASR Only Per Rule Exclusions in Profile1 to exempt the Adobe Reader plug-in from the blocking rule.

You have a Microsoft 365 E5 subscription. You use Microsoft Intune to manage all Windows 11 devices. You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile1 to all the devices. A user reports that an Adobe Reader plug-in is now blocked. You need to ensure that the plug-in is unblocked. What should you do?

  1. Create an Endpoint Privilege Management policy and assign the policy to all the devices.
  2. Add a scope tag to Profile1.
  3. Configure ASR Only Per Rule Exclusions in Profile1. Correct Answer
  4. Create a device compliance policy and assign the policy to all the devices.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to remediate an ASR policy blocking a legitimate application by using per-rule exclusions, rather than changing unrelated policies.

When an Attack Surface Reduction (ASR) policy blocks a legitimate application plug-in, you must configure exclusions within the ASR profile. This page explains how to unblock the Adobe Reader plug-in by modifying the ASR policy exclusions.

Choosing Endpoint Privilege Management (A) or Device Compliance (D) because they sound like security or management policies, but they do not configure ASR rule exclusions.

Community Discussion (4 comments)

ergacharsk 👍 1 Selected: C
C seems corret
ergacharsk 👍 1
C seems corret
servL 👍 2
Answer appears correct. Endpoint Privilege Management policy enables users to run tasks requiring elevated privilege without administrator rights. Scope tags determine which objects admins can see. Device Compliance Policy wouldn't impact ASR policy
chafe 👍 2 Selected: C
Only C makes sense in the context of the question, seems correct.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Configuring ASR Only Per Rule Exclusions in Profile1 allows an administrator to define specific processes, files, or folders that are exempt from the attack surface reduction rules. Since the Adobe Reader plug-in was blocked by Profile1, adding an exclusion for it directly resolves the issue without disabling the protection for the rest of the environment.

Why the Other Options Are Wrong

Endpoint Privilege Management (A) is used to allow standard users to run applications that require elevated privileges, which does not address ASR rule blocking. Scope tags (B) are strictly for delegating administrative visibility via Role-Based Access Control (RBAC) and have no effect on policy enforcement or exclusions. A device compliance policy (D) evaluates device settings for compliance status but cannot override or exclude an endpoint security configuration like an ASR rule.

Community Comment Notes

Commenters agreed that only option C makes sense in this context. As servL noted, "Endpoint Privilege Management policy enables users to run tasks requiring elevated privilege" and "Scope tags determine which objects admins can see," neither of which unblocks an ASR rule.

Official Reference

Exam Strategy

When an Intune ASR policy blocks a legitimate application, look for the option that modifies exclusions within the ASR profile itself. Do not confuse privilege management or compliance policies with endpoint security rule exclusions.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide