How to block Office applications from creating child processes in Microsoft 365?

Implement and manage endpoint protection by using Microsoft Defender for Endpoint Review and respond to security reports and alerts generated by Microsoft Defender XDR
Answer Correct answer: D — Create an attack surface reduction (ASR) policy that enables the Block Office applications from creating child processes rule.

You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender XDR. All users have devices that run Windows 11. From the Microsoft Defender portal, you review the Microsoft Secure Score recommendations. One of the top recommendations is to block all Microsoft Office applications from creating child processes. You need to increase the secure score by addressing the recommendation. What should you do?

  1. Select Safe Documents for Office clients.
  2. Create a policy for Office applications.
  3. Configure an endpoint detection and response (EDR) policy.
  4. Create an attack surface reduction (ASR) policy. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can map a Secure Score recommendation's exact wording to the matching ASR rule, and the trap is that the recommendation text sounds like a generic 'Office application policy' rather than an endpoint hardening rule.

Microsoft Secure Score recommends blocking all Office applications from creating child processes, a recommendation satisfied only by an attack surface reduction (ASR) policy in Microsoft Defender for Endpoint. This page confirms that creating an ASR policy (D) is the action that raises the score, and explains why Safe Documents, EDR and generic Office policies do not.

Choosing 'Create a policy for Office applications' (B) because the recommendation is about Office apps — no Office cloud policy, app protection policy or app configuration profile controls whether Winword.exe, Excel.exe or Outlook.exe can spawn child processes.

Community Discussion (3 comments)

Krayzr 👍 2 Selected: D
Block all Office applications from creating child processes >> Yes https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference#attack-surface-reduction-rules-by-type
KoenJas 👍 3
D. Create an attack surface reduction (ASR) policy.
Preeb 👍 4
ASR Policy is correct.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Secure Score surfaces 'Block all Office applications from creating child processes' as an improvement action, and that string is the verbatim name of an attack surface reduction (ASR) rule shipped with Microsoft Defender for Endpoint (rule GUID d4f940ab-401b-4efc-aadc-ad5f3c50688a). Because the scenario includes Intune, Defender XDR and Windows 11 devices, the rule is deployed through an Intune endpoint security attack surface reduction policy (or the equivalent ASR configuration in the Defender portal), which is exactly what option D describes. Once the ASR policy targets the Windows 11 device groups, the recommendation moves to 'Completed' and the tenant's Secure Score increases, since ASR rules are scored as configuration-based improvement actions. No other option in the list configures an ASR rule, so only D can satisfy the recommendation as written.

Why the Other Options Are Wrong

Option A, Safe Documents, is a Microsoft Defender for Office 365 feature that opens untrusted files in Protected View before a user can edit them; it addresses malicious attachments and documents, not process-creation behaviour on the endpoint, so it never clears this recommendation. Option B, 'Create a policy for Office applications', is the classic distractor: Office cloud policy service and Intune app protection/app configuration policies manage settings such as macros, COM add-ins or telemetry, but they cannot block an Office process from spawning cmd.exe or powershell.exe. Option C, an EDR policy, only onboards devices to Microsoft Defender for Endpoint and configures EDR capabilities such as automatic investigation and remediation, tamper protection or sample collection — it does not enforce ASR block rules. All three leave the Windows 11 devices without the process-creation restriction that Secure Score is measuring.

Community Comment Notes

Every learner answer recorded on this item agrees with D, and the reasoning is short and specific rather than a blind majority vote. Krayzr reproduced the recommendation wording — "Block all Office applications from creating child processes >> Yes" — and linked the official attack surface reduction rules reference, which is the definitive source that names this rule. Preeb simply stated "ASR Policy is correct." and KoenJas likewise selected D, so there is no dissent or counter-argument to weigh against the technical mapping between the recommendation name and the ASR rule.

Official Reference

Exam Strategy

Memorise the ASR rule names verbatim, because MS-102 questions frequently quote a Secure Score recommendation or Defender report and expect you to translate it into the matching rule or policy type. If you see 'child processes', 'Office applications' or 'process creation' in an endpoint scenario, reach for ASR rather than Safe Documents, EDR onboarding or an Office app policy.

Frequently Asked Questions

Why is an EDR policy not enough to block Office apps from creating child processes?

An EDR policy only onboards Windows 11 devices to Defender for Endpoint and configures investigation, remediation and tamper protection settings. Blocking process creation requires an ASR rule, which is delivered through an attack surface reduction policy.

Can Safe Documents for Office clients clear this Secure Score recommendation?

No. Safe Documents opens untrusted files in Protected View in Defender for Office 365 and has no control over whether Word, Excel or Outlook spawn child processes on the endpoint, so the ASR recommendation stays open.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide