Configuring Antivirus with Tamper Protection Enabled

Answer Correct answer: C — Enable troubleshooting mode to temporarily allow configuration of antivirus and real-time protection settings on Device1.

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. Defender for Endpoint has tamper protection enabled. You have a device named Device1 that is onboarded to Defender for Endpoint. You need to configure antivirus and real-time protection for Device1. What should you do in the Microsoft Defender portal?

  1. Initiate a live response session.
  2. Create a device group.
  3. Enable troubleshooting mode. Correct Answer
  4. Isolate Device1.

Community Votes

C
71%
B
29%

71% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of how to bypass tamper protection locks on individual devices without disabling the feature globally.

This page explains how to manage Microsoft Defender for Endpoint settings when tamper protection restricts local changes. It identifies troubleshooting mode as the correct method to temporarily override these restrictions for configuration tasks.

Candidates often select 'Create a device group' (B) because they think policy assignment is needed, but groups cannot override active tamper protection on an already onboarded device.

Community Discussion (6 comments)

atre_01 👍 7 Selected: C
The correct answer is: C. Enable troubleshooting mode. Enabling troubleshooting mode in Microsoft Defender for Endpoint allows you to configure settings, including antivirus and real-time protection, on a device that has tamper protection enabled. This mode helps ensure that necessary changes can be made without interference from existing security measures.
joaquim.gomes.pt 👍 6 Selected: B
To configure antivirus and real-time protection for Device1 in the Microsoft Defender portal, you should create a device group and assign the appropriate security policies to it.
kaspen 👍 3 Selected: C
When tamper protection is enabled, certain security settings, including antivirus and real-time protection, are locked to prevent unauthorized changes. Troubleshooting Mode: Enabling troubleshooting mode allows you to temporarily disable tamper protection so that you can make necessary configuration changes, such as adjusting antivirus and real-time protection settings.
justITtopics 👍 2 Selected: C
Answer C. https://learn.microsoft.com/en-us/defender-endpoint/manage-tamper-protection-microsoft-365-defender#important-points-to-keep-in-mind "When you enable tamper protection in the Microsoft Defender portal, the setting is applied tenant wide and restricts tamper-protected settings to their secure defaults. Any changes made to tamper-protected settings are ignored. Depending on your particular scenario, you have several options available: If you must make changes to a device and those changes are blocked by tamper protection, you can use troubleshooting mode to temporarily disable tamper protection on the device."
hola1010 👍 3 Selected: C
Troubleshooting mode Local admins, with appropriate permissions, can change configurations on individual endpoints that are usually locked by policy. Having a device in troubleshooting mode can be helpful when diagnosing Microsoft Defender Antivirus performance and compatibility scenarios. Local admins can't turn off Microsoft Defender Antivirus, or uninstall it. Local admins can configure all other security settings in the Microsoft Defender Antivirus suite (for example, cloud protection, tamper protection). Device groups: evice groups and use them to: Limit access to related alerts and data to specific Microsoft Entra user groups with assigned RBAC roles Configure different auto-remediation settings for different sets of devices Assign specific remediation levels to apply during automated investigations In an investigation, filter the Devices list to specific device groups by using the Group filter.
KoenJas 👍 1
C. Enable troubleshooting mode.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Correct answer: C — Enable troubleshooting mode to configure antivirus and real-time protection. When tamper protection is enabled in Microsoft Defender for Endpoint, it prevents unauthorized users from changing critical security settings, including turning off real-time protection. To make necessary configuration changes on a specific device like Device1, you must enable Troubleshooting Mode. This mode temporarily allows local administrators or specific actions to modify tamper-protected settings without requiring a tenant-wide change or uninstalling the agent.

Why the Other Options Are Wrong

Option A (Initiate a live response session) is used for remote command-line execution and investigation, not for persistently configuring antivirus policies. Option B (Create a device group) is a way to organize devices for policy assignment, but it does not bypass the immediate lock imposed by tamper protection on an existing device. Option D (Isolate Device1) severs network connectivity to protect against threats and does not assist in configuring antivirus settings.

Community Comment Notes

Community consensus strongly supports option C. As noted in comment, enabling troubleshooting mode allows configuration changes that are otherwise locked. Comment references official Microsoft documentation confirming that tamper protection ignores changes unless troubleshooting mode is active. While some learners suggested device groups, the technical constraint of tamper protection makes troubleshooting mode the only viable direct action for this scenario.

Official Reference

Exam Strategy

Always distinguish between global policy management and immediate device-level overrides. When 'tamper protection' is mentioned, look for 'troubleshooting mode' if the goal is to make changes on a specific endpoint.

Frequently Asked Questions

Does enabling troubleshooting mode disable tamper protection permanently?

No, it is a temporary state that can be toggled on or off as needed for troubleshooting or configuration.

Can I use a device group to override tamper protection?

No, device groups manage policy assignments but do not bypass the runtime enforcement of tamper protection on individual endpoints.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide