Microsoft Defender for Endpoint
Vulnerabilities and exposure

Attack Surface Reduction Rules Overview

In brief

Starting with platform version 4.18.26060, using the Unblock option to override an ASR rule in Warn mode requires administrator approval. Per-ASR rule exclusions should be used for persistent exceptions.

What Defender admins need to know

Administrators must approve Unblock overrides and configure per-ASR rule exclusions when a durable exception is needed.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • m365-security
  • tier2
  • mde-asr ms.date: 07/02/08/04/2026 ai-usage: ai-assisted

#customer intent: As an IT admin, I want to understand attack surface reduction rules so I can protect Windows devices from common malware attack vectors. appliesto: For more information about modes in Microsoft Defender Antivirus, see How Microsoft Defender Antivirus affects Defender for Endpoint functionality.

Supported operating systems for ASR rules

|Not configured|5|The ASR rule isn't explicitly enabled.

This value is functionally equivalent to Disabled or Off, but without the potential for rule conflicts.| |Warn or
Warning|6|The ASR rule is enabled as if in Block mode, but users can select Unblock in the warning notification pop-up to bypass the block for 24 hours. After 24 hours, the user needs to bypass the block again.

Warn mode is supported in Windows 10 version 1809 (November 2018) or later. ASR rules in Warn mode on unsupported versions of Windows are effectively in Block mode (bypass isn't available).

Warn mode isn't available in Microsoft Configuration Manager.

Warn mode has the following Microsoft Defender Antivirus version requirements:

  • Platform release: 4.18.2008.9 (August 2020) or later.
  • Engine release: 1.1.17400.5 (August 2020) or later.

The following ASR rules don't support Warn mode: |

Microsoft recommends Block mode for the standard protection rules, and initial testing in Audit mode for other ASR rules before activating them in Block or Warn mode.

Many line-of-business applications are written with limited security concerns, and they might act in ways that seem similar to malware. By monitoring data from ASR rules in Audit mode and adding exclusions for required apps, you can deploy ASR rules without reducing productivity.

Nonconflicting ASR rules don't result in errors. The first rule is applied, and subsequent nonconflicting rules are merged into the policy.

If a mobile device management (MDM) solution and Group Policy apply different ASR rule settings to the same device, the Group Policy settings take precedence.takes precedence by default. You can change this behavior with the MDMWinsOverGP Policy CSP setting, or avoid the conflict entirely by using controlled configuration. For more information, see How policy conflicts are handled.

For information about how ASR rule setting conflicts are handled for the available deployment methods in Microsoft Intune, see Devices managed by Intune.

Notifications and alerts for ASR rules

When an ASR rule in Block or Warn mode is triggered on a device, a notification is displayed on the device. You can customize the information in the notifications. For more information, see Customize contact information in Windows SecurityCustomize contact information in Windows Security.

Endpoint Detection and Response (EDR) alerts in Defender for Endpoint are generated when supported ASR rules are triggered.