Preventing Users from Disabling Microsoft Defender for Endpoint
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender Antivirus on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of Microsoft 365 Defender's Tamper Protection feature, which specifically blocks unauthorized changes to security settings, a common trap where candidates might look for Intune policies instead.
This question addresses how to enforce security settings on Azure AD-joined devices managed by Intune. The correct approach is enabling Tamper Protection via the Microsoft 365 Defender portal to prevent users from disabling key security components.
Candidates often choose Option C (Account Protection Policy) because it is an Intune policy, but Account Protection focuses on Windows Hello and Credential Guard, not on preventing the disabling of the antivirus engine itself.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Tamper Protection is a feature in Microsoft Defender for Endpoint that prevents malware or unauthorized users from disabling critical security features, including turning off real-time protection or changing settings. To configure this, you must enable it in the Microsoft 365 Defender portal (formerly Microsoft 365 Security). Once enabled, it applies to all enrolled devices, ensuring that even administrators with local admin rights cannot easily disable it without first turning off Tamper Protection globally or via a specific override.Why the Other Options Are Wrong
Option A (ASR Policy) is used to block malicious behaviors like Office macros or script execution, not to lock down antivirus settings. Option C (Account Protection Policy) in Intune configures Windows Hello for Business and FIDO2 keys, which are authentication methods, not endpoint defense mechanisms. Option D (Conditional Access) controls access to resources based on identity and device state but does not manage local security agent configurations like antivirus status.Community Comment Notes
The community overwhelmingly selected B, confirming the consensus. One user noted that Tamper Protection protects settings "such as virus and threat protection" from being disabled. Another comment clarified that while some might confuse the management portal, the configuration for Tamper Protection resides in the Microsoft 365 Defender portal, not Intune directly, although Intune enforces the enrollment.Official Reference
Exam Strategy
When asked about preventing users from modifying security agents, always consider 'Tamper Protection' first. Remember that Tamper Protection is configured centrally in the Microsoft 365 Defender portal, not in Intune policies, even though Intune manages the device enrollment.
Frequently Asked Questions
Can I enable Tamper Protection via Intune?
No, Tamper Protection is enabled centrally in the Microsoft 365 Defender portal. Intune does not have a native setting to toggle this specific feature.
What does Account Protection Policy do?
It configures Windows Hello for Business, FIDO2 security keys, and Credential Guard, but it does not control antivirus disablement permissions.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →