Scoping Microsoft Defender XDR deception rules to specific devices with device tags
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Deception rules in Defender XDR target devices through device tags, not device groups; tagging the intended machines first lets you scope the rule to exactly those devices while keeping the configuration simple.
You must implement Defender XDR deception rules and limit their scope to specific devices; the first thing to create is device tags, because deception rules scope their lures to devices by tag rather than by device group.
Choosing device groups because they are familiar from other Defender features — the deception rule scoping control offers device tags, not device groups, so a group cannot limit the rule's scope.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Deception rules in Microsoft Defender XDR are scoped in the rule's scope section, where you choose to plant lures on all Windows client devices or only on clients that carry specific device tags. Creating the device tags first is therefore the prerequisite step that lets you limit the rule to the intended machines.Why the Other Options Are Wrong
Device groups (A) are used elsewhere in Defender for Endpoint but are not offered as a scoping mechanism inside the deception rule wizard, so they cannot limit the rule's scope. Honeytoken entity tags (C) and sensitive entity tags (D) are classifications you apply to discovered entities (users, devices, secrets) to flag them as decoys or high-value, not the mechanism that scopes where lures are planted.Community Comment Notes
Dogfather and WinstonN both cite https://learn.microsoft.com/en-us/defender-xdr/configure-deception and note there is no device-group option when configuring a deception rule, only device tags. ExamSC200 adds that device tags give more granular control than device groups for this purpose.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →