Prevent Users Disabling Defender for Endpoint

Configure endpoint security
Answer Correct answer: B — From the Microsoft Intune admin center, create an antivirus policy to enforce tamper protection.

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

  1. From the Microsoft Intune admin center, create a security baseline.
  2. From the Microsoft Intune admin center, create an antivirus policy. Correct Answer
  3. From the Microsoft Entra admin center, create a Conditional Access policy.
  4. From the Microsoft Intune admin center, create a device compliance policy.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to configure Microsoft Defender for Endpoint via Intune, specifically identifying that an antivirus policy is used to enforce tamper protection rather than a broader security baseline or compliance policy.

Managing Microsoft Defender for Endpoint settings on Intune-enrolled Windows 11 devices requires configuring an antivirus policy. This page establishes that creating an antivirus policy in the Microsoft Intune admin center is the correct method to enforce tamper protection and prevent users from disabling the antivirus.

Choosing a security baseline (Option A) is a common mistake because while baselines include some Defender settings, the dedicated and direct method to manage Defender-specific configurations like tamper protection is through an antivirus policy.

Community Discussion (9 comments)

AleFCI1908 👍 7 Selected: B
In similar previous questions, the keyword was 'tamper.' Now I've learned the steps necessary to apply tamper protection... thanks to the exam topics.
Krayzr 👍 5 Selected: B
The correct answer is B. From the Microsoft Intune admin center, create an antivirus policy. Here’s the reasoning: Microsoft Defender for Endpoint is an antivirus solution, and its settings can be managed through an antivirus policy in Microsoft Intune. This includes settings that prevent users from disabling the antivirus. Therefore, creating an antivirus policy in the Microsoft Intune admin center would be the appropriate action to take. Option A, creating a security baseline, is not the best choice because security baselines are predefined sets of recommended security settings that might not cover the specific requirement of preventing users from disabling Microsoft Defender for Endpoint. Option C, creating a Conditional Access policy in the Microsoft Entra admin center, is not applicable because Conditional Access policies are used to enforce access controls based on conditions, not to manage antivirus settings. Option D, creating a device compliance policy, is also not the best choice because device compliance policies are used to determine whether a device is compliant with the organization’s rules, not to manage antivirus settings.
Meek_Learner 👍 1
To prevent users from disabling Microsoft Defender for Endpoint on Windows 11 computers managed through Microsoft Intune, you should create an antivirus policy from the Microsoft Intune admin center. Antivirus policies in Intune allow administrators to enforce Microsoft Defender security settings, ensuring that users cannot disable key protection features. The antivirus policy will include settings to: Enable Tamper Protection, preventing users from modifying security settings. Ensure real-time protection remains enabled. Configure attack surface reduction rules to enhance endpoint security. By using an antivirus policy, you can enforce and maintain Microsoft Defender for Endpoint configurations effectively across your organization's devices.
bigreg 👍 1 Selected: B
I checked it
3661de6 👍 1 Selected: B
B is correct
kerimnl 👍 1 Selected: B
B is correct answer
Darkfire 👍 2 Selected: B
B should be correct based on: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-tamper-protection-intune?view=o365-worldwide#:~:text=In%20the%20Intune%20admin%20center%2C%20go,Deploy%20the%20policy%20to%20devices.
CaTa_LySt 👍 1
To prevent users from disabling Microsoft Defender for Endpoint on the Windows 11 computers enrolled in Microsoft Intune, you should: A. From the Microsoft Intune admin center, create a security baseline. Security baselines in Microsoft Intune provide a set of pre-configured Windows settings and recommended configurations to help secure your devices. By creating a security baseline, you can enforce specific security settings, including those related to Microsoft Defender for Endpoint. This ensures that the recommended security configurations are applied to the Windows 11 computers, and users are prevented from disabling Microsoft Defender for Endpoint. Option B (creating an antivirus policy) might be related to specific settings for Microsoft Defender Antivirus, but using a security baseline is a more comprehensive approach. Options C (Conditional Access policy) and D (device compliance policy) are typically used for access control and compliance checks but may not specifically address the prevention of users disabling Microsoft Defender for Endpoint.
kiro_e 👍 3
Could be B, isn't it?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating an antivirus policy in the Microsoft Intune admin center (Endpoint security > Antivirus) allows administrators to directly configure Microsoft Defender Antivirus settings, including turning on tamper protection. Tamper protection restricts local users from disabling or altering Defender settings, directly fulfilling the requirement to prevent users from disabling Microsoft Defender for Endpoint.

Why the Other Options Are Wrong

A security baseline (Option A) applies a broad set of pre-configured security settings and is not the dedicated tool for managing specific Defender antivirus configurations. A Conditional Access policy (Option C) controls access to cloud resources based on compliance signals but cannot configure local antivirus agent settings. A device compliance policy (Option D) evaluates whether a device meets organizational rules but does not deploy the configuration to enforce those rules, such as preventing users from disabling Defender.

Community Comment Notes

Commenters overwhelmingly agree that an antivirus policy is the correct approach to manage tamper protection. As Darkfire noted, the official documentation explicitly directs administrators to the "Intune admin center" to "Deploy the policy to devices" for tamper protection. AleFCI1908 also highlighted that the keyword "tamper" is crucial for understanding this configuration.

Official Reference

Exam Strategy

When asked to configure specific Microsoft Defender for Endpoint settings like tamper protection in Intune, look for the Endpoint Security Antivirus policy. Avoid security baselines unless the question specifically asks for a baseline or a broad set of recommended security configurations.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide