What Does Semi-Require Approval for Non-Temp Folders Do in Defender XDR?
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi – require approval for non-temp folders for the endpoints. You need to identify the impact of the Automation level setting on the endpoints. Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Community Votes
66% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the difference between the core-folders and non-temp-folders automation levels — the trap is assuming that system folders like \windows\ or \program files (x86)\ are still auto-remediated once approval is required for non-temporary folders.
Microsoft Defender for Endpoint automation levels decide which folders are remediated automatically and which are only remediated after approval. At Semi – require approval for non-temp folders, non-temporary paths such as \program files (x86)\ and \windows\ are held for approval (A), while user download/temp paths such as \users\*\downloads\ are cleaned automatically (D).
Choosing AC or BD, which assume \windows\ or \program files (x86)\ is remediated automatically. Both are non-temporary (core) folders, so at this level a threat there becomes a pending action that must be approved instead of being cleaned automatically.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
With the automation level set to Semi – require approval for non-temp folders, Defender for Endpoint only auto-remediates threats located in temporary folders; every other location produces a pending remediation action that must be approved, which is exactly what option A describes. Option D fits because \users\*\downloads\ is a user download/temporary location, so a threat detected in a user's Downloads folder is remediated automatically without any approval step. Taken together, the two observable effects of this setting are approval-gated remediation outside temp folders (A) and automatic remediation inside download/temp paths (D). Any answer that keeps a system path in the automatic bucket does not match this specific automation level.Why the Other Options Are Wrong
Option B treats \program files (x86)\ as a temporary folder, but it is a program/core path, so remediation there requires approval at this level rather than running automatically. Option C makes the same error for \windows\: as wafferrr noted, "\Windows\* is not a temp folder but rather a core folder", and core folders are only auto-remediated at the Full – remediate threats automatically level (or approval-gated at the core-folders level). Because both B and C assert automatic remediation in non-temporary system folders, both are incompatible with the configured level. That leaves A and D as the only pair of effects that actually occur.Community Comment Notes
Most voters converged on AD, and kaspen captured the logic well: non-temporary folders such as Program Files (x86) and Windows need approval, while the Downloads folder is remediated automatically. Ody pushed back with "Correct answer is given: B and D" and pointed readers to the Microsoft levels-of-automation page for the definition of temporary folders, but treating \program files (x86)\ as temporary contradicts the core/non-temp folder distinction that the same page draws, so that reading is not defensible. wafferrr's remark that \Windows\ belongs to core-folder handling is a useful reminder that the three semi-automatic levels are nested by restrictiveness, not interchangeable.Official Reference
Exam Strategy
Map each folder in the answer choices to its category (temporary, core/non-temp, or user) before reading the automation level, then apply the level's rule to that category. Microsoft's three semi-automatic levels are cumulative in restrictiveness, so a folder that is a core/non-temp path always needs approval unless the level is Full.
Frequently Asked Questions
Why is \windows\ not remediated automatically with the non-temp folders setting?
C:\Windows is a core, non-temporary folder, so only the Full – remediate threats automatically level cleans threats there without approval.
Is \users\*\downloads\* treated as a temporary folder by Defender for Endpoint?
Yes. User download and temp paths count as temporary folders, so a threat there is auto-remediated at the non-temp folders level.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →