Trouble Finding ASR Policies in Intune and MDE

0
5
Asked By TechWhiz92 On

I'm working with a client who has 14 Attack Surface Reduction (ASR) rules applied to their computer, but only 6 of these are showing up in Intune. It's puzzling because I also noticed that there are no ASR configurations in Intune's endpoint security under security baselines, and the same goes for MDE—there's nothing listed in the configuration management's enforcement scope. I have the setting to enforce security config from Intune turned on, yet I can't find where these additional policies are coming from. I'm really stuck and would appreciate any guidance on this issue!

3 Answers

Answered By Entegy On

Have you checked the Endpoint Security section under Attack Surface Reduction? If nothing shows up there, it might be an indication that the policies are being applied from another source.

Answered By TimePlankton3171 On

It might be worth checking for local policies that could be adding these rules. Sometimes users run things that modify the registry directly. A good spot to look is ```HKLMSOFTWAREPoliciesMicrosoftWindows DefenderWindows Defender Exploit GuardASRRules```.

Answered By joshghz On

You could try resetting the policies using PowerShell to see if they get reapplied. Excluding the client from all Intune policies temporarily might also help to identify how these settings are being enforced.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.