How to block Office applications from creating child processes in Microsoft 365?
You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender XDR. All users have devices that run Windows 11. From the Microsoft Defender portal, you review the Microsoft Secure Score recommendations. One of the top recommendations is to block all Microsoft Office applications from creating child processes. You need to increase the secure score by addressing the recommendation. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can map a Secure Score recommendation's exact wording to the matching ASR rule, and the trap is that the recommendation text sounds like a generic 'Office application policy' rather than an endpoint hardening rule.
Microsoft Secure Score recommends blocking all Office applications from creating child processes, a recommendation satisfied only by an attack surface reduction (ASR) policy in Microsoft Defender for Endpoint. This page confirms that creating an ASR policy (D) is the action that raises the score, and explains why Safe Documents, EDR and generic Office policies do not.
Choosing 'Create a policy for Office applications' (B) because the recommendation is about Office apps — no Office cloud policy, app protection policy or app configuration profile controls whether Winword.exe, Excel.exe or Outlook.exe can spawn child processes.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Secure Score surfaces 'Block all Office applications from creating child processes' as an improvement action, and that string is the verbatim name of an attack surface reduction (ASR) rule shipped with Microsoft Defender for Endpoint (rule GUID d4f940ab-401b-4efc-aadc-ad5f3c50688a). Because the scenario includes Intune, Defender XDR and Windows 11 devices, the rule is deployed through an Intune endpoint security attack surface reduction policy (or the equivalent ASR configuration in the Defender portal), which is exactly what option D describes. Once the ASR policy targets the Windows 11 device groups, the recommendation moves to 'Completed' and the tenant's Secure Score increases, since ASR rules are scored as configuration-based improvement actions. No other option in the list configures an ASR rule, so only D can satisfy the recommendation as written.Why the Other Options Are Wrong
Option A, Safe Documents, is a Microsoft Defender for Office 365 feature that opens untrusted files in Protected View before a user can edit them; it addresses malicious attachments and documents, not process-creation behaviour on the endpoint, so it never clears this recommendation. Option B, 'Create a policy for Office applications', is the classic distractor: Office cloud policy service and Intune app protection/app configuration policies manage settings such as macros, COM add-ins or telemetry, but they cannot block an Office process from spawning cmd.exe or powershell.exe. Option C, an EDR policy, only onboards devices to Microsoft Defender for Endpoint and configures EDR capabilities such as automatic investigation and remediation, tamper protection or sample collection — it does not enforce ASR block rules. All three leave the Windows 11 devices without the process-creation restriction that Secure Score is measuring.Community Comment Notes
Every learner answer recorded on this item agrees with D, and the reasoning is short and specific rather than a blind majority vote. Krayzr reproduced the recommendation wording — "Block all Office applications from creating child processes >> Yes" — and linked the official attack surface reduction rules reference, which is the definitive source that names this rule. Preeb simply stated "ASR Policy is correct." and KoenJas likewise selected D, so there is no dissent or counter-argument to weigh against the technical mapping between the recommendation name and the ASR rule.Official Reference
Exam Strategy
Memorise the ASR rule names verbatim, because MS-102 questions frequently quote a Secure Score recommendation or Defender report and expect you to translate it into the matching rule or policy type. If you see 'child processes', 'Office applications' or 'process creation' in an endpoint scenario, reach for ASR rather than Safe Documents, EDR onboarding or an Office app policy.
Frequently Asked Questions
Why is an EDR policy not enough to block Office apps from creating child processes?
An EDR policy only onboards Windows 11 devices to Defender for Endpoint and configures investigation, remediation and tamper protection settings. Blocking process creation requires an ASR rule, which is delivered through an attack surface reduction policy.
Can Safe Documents for Office clients clear this Secure Score recommendation?
No. Safe Documents opens untrusted files in Protected View in Defender for Office 365 and has no control over whether Word, Excel or Outlook spawn child processes on the endpoint, so the ASR recommendation stays open.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →