Configuring Antivirus with Tamper Protection Enabled
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. Defender for Endpoint has tamper protection enabled. You have a device named Device1 that is onboarded to Defender for Endpoint. You need to configure antivirus and real-time protection for Device1. What should you do in the Microsoft Defender portal?
Community Votes
71% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of how to bypass tamper protection locks on individual devices without disabling the feature globally.
This page explains how to manage Microsoft Defender for Endpoint settings when tamper protection restricts local changes. It identifies troubleshooting mode as the correct method to temporarily override these restrictions for configuration tasks.
Candidates often select 'Create a device group' (B) because they think policy assignment is needed, but groups cannot override active tamper protection on an already onboarded device.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Correct answer: C — Enable troubleshooting mode to configure antivirus and real-time protection. When tamper protection is enabled in Microsoft Defender for Endpoint, it prevents unauthorized users from changing critical security settings, including turning off real-time protection. To make necessary configuration changes on a specific device like Device1, you must enable Troubleshooting Mode. This mode temporarily allows local administrators or specific actions to modify tamper-protected settings without requiring a tenant-wide change or uninstalling the agent.Why the Other Options Are Wrong
Option A (Initiate a live response session) is used for remote command-line execution and investigation, not for persistently configuring antivirus policies. Option B (Create a device group) is a way to organize devices for policy assignment, but it does not bypass the immediate lock imposed by tamper protection on an existing device. Option D (Isolate Device1) severs network connectivity to protect against threats and does not assist in configuring antivirus settings.Community Comment Notes
Community consensus strongly supports option C. As noted in comment, enabling troubleshooting mode allows configuration changes that are otherwise locked. Comment references official Microsoft documentation confirming that tamper protection ignores changes unless troubleshooting mode is active. While some learners suggested device groups, the technical constraint of tamper protection makes troubleshooting mode the only viable direct action for this scenario.Official Reference
Exam Strategy
Always distinguish between global policy management and immediate device-level overrides. When 'tamper protection' is mentioned, look for 'troubleshooting mode' if the goal is to make changes on a specific endpoint.
Frequently Asked Questions
Does enabling troubleshooting mode disable tamper protection permanently?
No, it is a temporary state that can be toggled on or off as needed for troubleshooting or configuration.
Can I use a device group to override tamper protection?
No, device groups manage policy assignments but do not bypass the runtime enforcement of tamper protection on individual endpoints.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →