Prevent Users Disabling Defender for Endpoint
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to configure Microsoft Defender for Endpoint via Intune, specifically identifying that an antivirus policy is used to enforce tamper protection rather than a broader security baseline or compliance policy.
Managing Microsoft Defender for Endpoint settings on Intune-enrolled Windows 11 devices requires configuring an antivirus policy. This page establishes that creating an antivirus policy in the Microsoft Intune admin center is the correct method to enforce tamper protection and prevent users from disabling the antivirus.
Choosing a security baseline (Option A) is a common mistake because while baselines include some Defender settings, the dedicated and direct method to manage Defender-specific configurations like tamper protection is through an antivirus policy.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Creating an antivirus policy in the Microsoft Intune admin center (Endpoint security > Antivirus) allows administrators to directly configure Microsoft Defender Antivirus settings, including turning on tamper protection. Tamper protection restricts local users from disabling or altering Defender settings, directly fulfilling the requirement to prevent users from disabling Microsoft Defender for Endpoint.Why the Other Options Are Wrong
A security baseline (Option A) applies a broad set of pre-configured security settings and is not the dedicated tool for managing specific Defender antivirus configurations. A Conditional Access policy (Option C) controls access to cloud resources based on compliance signals but cannot configure local antivirus agent settings. A device compliance policy (Option D) evaluates whether a device meets organizational rules but does not deploy the configuration to enforce those rules, such as preventing users from disabling Defender.Community Comment Notes
Commenters overwhelmingly agree that an antivirus policy is the correct approach to manage tamper protection. As Darkfire noted, the official documentation explicitly directs administrators to the "Intune admin center" to "Deploy the policy to devices" for tamper protection. AleFCI1908 also highlighted that the keyword "tamper" is crucial for understanding this configuration.Official Reference
Exam Strategy
When asked to configure specific Microsoft Defender for Endpoint settings like tamper protection in Intune, look for the Endpoint Security Antivirus policy. Avoid security baselines unless the question specifically asks for a baseline or a broad set of recommended security configurations.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →