Preventing Users from Disabling Microsoft Defender for Endpoint

Answer Correct answer: B — Enable tamper protection from the Microsoft 365 Defender portal to prevent users from disabling Microsoft Defender for Endpoint.

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender Antivirus on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

  1. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
  2. From the Microsoft 365 Defender portal, enable tamper protection. Correct Answer
  3. From the Microsoft Intune admin center, create an account protection policy.
  4. From the Microsoft Entra admin center, create a Conditional Access policy.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of Microsoft 365 Defender's Tamper Protection feature, which specifically blocks unauthorized changes to security settings, a common trap where candidates might look for Intune policies instead.

This question addresses how to enforce security settings on Azure AD-joined devices managed by Intune. The correct approach is enabling Tamper Protection via the Microsoft 365 Defender portal to prevent users from disabling key security components.

Candidates often choose Option C (Account Protection Policy) because it is an Intune policy, but Account Protection focuses on Windows Hello and Credential Guard, not on preventing the disabling of the antivirus engine itself.

Community Discussion (11 comments)

OigresMG 👍 1
It seems that the correct option is: B. From the Microsoft 365 Defender portal, enable tamper protection.
Nizhnoynovogorod 👍 2 Selected: B
B - Enable Tamer Protection
MR_Eliot 👍 1
B is correct.
Krayzr 👍 1
Is this the LAST QUESTION you see? And leave a comment if you took the exam pls
Merrybob 👍 3 Selected: B
B. From the Microsoft 365 Defender portal, enable tamper protection. Ref: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-tamper-protection-intune?view=o365-worldwide#:~:text=Tamper%20protection%20helps%20protect%20certain%20security%20settings%2C%20such%20as%20virus%20and%20threat%20protection%2C%20from%20being%20disabled%20or%20changed.
Pasado 👍 2
Chatgpt: The correct option to prevent users from disabling Microsoft Defender for Endpoint is B. From the Microsoft 365 Defender portal, enable tamper protection.
Krayzr 👍 2 Selected: B
To prevent users from disabling Microsoft Defender for Endpoint, you can use Group Policy to hide the Microsoft Defender Antivirus interface from users and prevent them from pausing scans 12. This will ensure that users cannot disable Microsoft Defender Antivirus on their endpoints. Therefore, the correct answer is B. From the Microsoft 365 Defender portal, enable tamper protection 3. Tamper protection is a feature that prevents malicious actors from disabling Microsoft Defender Antivirus and other security features on endpoints. It is available in Microsoft Defender for Endpoint Plan 1 and Plan 2 3. Option A is incorrect because attack surface reduction (ASR) policies are used to reduce the attack surface of an organization’s devices by blocking or restricting certain types of activities 1. Option C is incorrect because account protection policies are used to protect user accounts from unauthorized access 1. Option D is incorrect because Conditional Access policies are used to control access to cloud apps and services based on specific conditions 1. Bing AI said ...
algar6767 👍 1
Respuesta correcta es la C: hay que crear un politica desde endpoint security/antivirus No existe el portal de microsft 365 defender y te ponen al final lo de tamper protecion para que te equivoques ENDPOINT ADMIN CENTER /ENDPOINT SECURITY/ANTIVIRUS /CREAR POLICY/ WINDOWS SECURITY ENTERPRISE/CONFIGURATON SETTINGS, DEFENDER, TAAMPERPROTECTION ENDPOINT ADMIN CENTER /ENDPOINT SECURITY/ANTIVIRUS /CREAR POLICY/ WINDOWS SECURITY ENTERPRISE/CONFIGURATON SETTINGS, DEFENDER, TAAMPERPROTECTION
IcE 👍 3 Selected: B
Tamper protection
NoursBear 👍 1
It's B without a doubt, this question is event a few pages before
mp34 👍 4
I think it is tamper protection. I have just checked the account protection settings, and you can configure Windows Hello, security keys for sign in and Credential Guard

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Tamper Protection is a feature in Microsoft Defender for Endpoint that prevents malware or unauthorized users from disabling critical security features, including turning off real-time protection or changing settings. To configure this, you must enable it in the Microsoft 365 Defender portal (formerly Microsoft 365 Security). Once enabled, it applies to all enrolled devices, ensuring that even administrators with local admin rights cannot easily disable it without first turning off Tamper Protection globally or via a specific override.

Why the Other Options Are Wrong

Option A (ASR Policy) is used to block malicious behaviors like Office macros or script execution, not to lock down antivirus settings. Option C (Account Protection Policy) in Intune configures Windows Hello for Business and FIDO2 keys, which are authentication methods, not endpoint defense mechanisms. Option D (Conditional Access) controls access to resources based on identity and device state but does not manage local security agent configurations like antivirus status.

Community Comment Notes

The community overwhelmingly selected B, confirming the consensus. One user noted that Tamper Protection protects settings "such as virus and threat protection" from being disabled. Another comment clarified that while some might confuse the management portal, the configuration for Tamper Protection resides in the Microsoft 365 Defender portal, not Intune directly, although Intune enforces the enrollment.

Official Reference

Exam Strategy

When asked about preventing users from modifying security agents, always consider 'Tamper Protection' first. Remember that Tamper Protection is configured centrally in the Microsoft 365 Defender portal, not in Intune policies, even though Intune manages the device enrollment.

Frequently Asked Questions

Can I enable Tamper Protection via Intune?

No, Tamper Protection is enabled centrally in the Microsoft 365 Defender portal. Intune does not have a native setting to toggle this specific feature.

What does Account Protection Policy do?

It configures Windows Hello for Business, FIDO2 security keys, and Credential Guard, but it does not control antivirus disablement permissions.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide