Prevent Disabling Defender for Endpoint

Configure endpoint security
Answer Correct answer: C — Enable tamper protection in the Microsoft Defender portal to prevent users from disabling Microsoft Defender for Endpoint.

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

  1. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
  2. From the Microsoft Intune admin center, create an account protection policy.
  3. From the Microsoft Defender portal, enable tamper protection. Correct Answer
  4. From the Microsoft Intune admin center, create a device compliance policy.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tamper protection is the specific feature required to prevent users from altering or disabling Microsoft Defender for Endpoint settings, catching those who confuse policy enforcement with local setting locks.

Microsoft Defender for Endpoint tamper protection prevents unauthorized users from disabling security settings. This page confirms that enabling tamper protection in the Microsoft Defender portal is the correct method to restrict these changes.

Choosing an ASR policy (A) or device compliance policy (D) because they seem related to security enforcement, but neither actually blocks the user from disabling the service locally.

Community Discussion (5 comments)

powered 👍 5 Selected: C
It looks similar/duplicate to other question post here, can someone pls chk?
correction 👍 1 Selected: C
Given Answer is correct
Meek_Learner 👍 1
To prevent users from disabling Microsoft Defender for Endpoint on the computers, you should enable tamper protection from the Microsoft Defender portal. Tamper protection is a critical feature that helps protect against unauthorized changes from users (and even malware) to security settings, including attempts to disable Microsoft Defender for Endpoint.
DiligentSam 👍 2
Given Answer is correct
meer.mariwan00 👍 2
what a glorious sight ( I reached the final question )

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Enabling tamper protection in the Microsoft Defender portal is the designated method to prevent users, including local administrators, from disabling Microsoft Defender for Endpoint or altering its core security settings. This feature locks down critical Defender configurations to ensure continuous, uninterrupted protection against threats.

Why the Other Options Are Wrong

An attack surface reduction (ASR) policy reduces attack vectors but does not block users from disabling the Defender agent itself. An account protection policy manages identity and access security, not antivirus settings. A device compliance policy evaluates whether a device meets baseline requirements and marks it compliant/non-compliant, but it does not actively prevent a user from turning off Defender locally.

Community Comment Notes

Community members strongly agree with the given answer, noting that "tamper protection is a critical feature that helps protect against unauthorized changes" to security settings. Others simply validated that the given answer is correct.

Official Reference

Exam Strategy

When asked how to prevent users from altering or disabling Defender settings, look for 'tamper protection'. Do not confuse compliance or ASR policies with the hard enforcement that blocks local changes.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide