Microsoft Defender for Endpoint
Endpoint protection

Address Unwanted Behaviors Mde

In brief

The page now emphasizes identifying the capability causing unwanted behavior and uses clearer links for viewing ASR detections and configuring exclusions. Documentation metadata was also updated.

What Defender admins need to know

Administrators can use the revised wording to navigate ASR investigation and exclusion guidance more easily. No action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Use exclusions, indicators, and other techniques to address false positives, performance issues, and app incompatibilities in Microsoft Defender for Endpoint. author: limwainstein ms.author: lwainstein ms.date: 06/16/07/03/2026 ms.topic: how-to ms.service: defender-endpoint ms.subservice: onboard ms.localizationpriority: medium ms.reviewer: joshbregman ms.custom:

  1. Depending on your findings fromabout which capability is causing the previous step,unwanted behavior, you might take one or more of the following actions:

In this scenario, a legitimate app is detected and identified as malicious by an attack surface reduction (ASR) rule in Microsoft Defender Antivirus. The ASR rule Block JavaScript or VBScript from launching downloaded executable content blocks any downloaded content when the user tries to use the app.

For the available methodsTo learn how to seeview ASR rule detections in Defender for Endpoint, see Monitor attack surface reduction (ASR) rule activity.

How to address:

Use the Attack surface reduction rules report to see the detections, affected devices, and affected files. In particular, you can download the full file and path information for the affected files to exclude from the ASR rule on the Add exclusions tab of the report.

For the available methodsTo learn how to configure ASR rule exclusions, see File and folder exclusions for ASR rules.

Word templates that contain macros that launch other apps are blocked

In this scenario, the ASR rule Block Win32 API calls from Office macros blocks Microsoft Word when a user opens documents created from Microsoft Word templates that contain macros, and those macros launch other applications.

For the available methodsTo learn how to seeview ASR rule detections in Defender for Endpoint, see Monitor attack surface reduction (ASR) rule activity.

How to address:

Use the Attack surface reduction rules report to see the detections, affected devices, and affected files. In particular, you can download the full file and path information for the affected files to exclude from the ASR rule on the Add exclusions tab of the report.

For the available methodsTo learn how to configure ASR rule exclusions, see File and folder exclusions for ASR rules.

See also