Prevent Disabling Defender for Endpoint
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tamper protection is the specific feature required to prevent users from altering or disabling Microsoft Defender for Endpoint settings, catching those who confuse policy enforcement with local setting locks.
Microsoft Defender for Endpoint tamper protection prevents unauthorized users from disabling security settings. This page confirms that enabling tamper protection in the Microsoft Defender portal is the correct method to restrict these changes.
Choosing an ASR policy (A) or device compliance policy (D) because they seem related to security enforcement, but neither actually blocks the user from disabling the service locally.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Enabling tamper protection in the Microsoft Defender portal is the designated method to prevent users, including local administrators, from disabling Microsoft Defender for Endpoint or altering its core security settings. This feature locks down critical Defender configurations to ensure continuous, uninterrupted protection against threats.Why the Other Options Are Wrong
An attack surface reduction (ASR) policy reduces attack vectors but does not block users from disabling the Defender agent itself. An account protection policy manages identity and access security, not antivirus settings. A device compliance policy evaluates whether a device meets baseline requirements and marks it compliant/non-compliant, but it does not actively prevent a user from turning off Defender locally.Community Comment Notes
Community members strongly agree with the given answer, noting that "tamper protection is a critical feature that helps protect against unauthorized changes" to security settings. Others simply validated that the given answer is correct.Official Reference
Exam Strategy
When asked how to prevent users from altering or disabling Defender settings, look for 'tamper protection'. Do not confuse compliance or ASR policies with the hard enforcement that blocks local changes.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →