Microsoft Defender for Endpoint
Endpoint protection

Configure advanced features in Microsoft Defender for Endpoint

In brief

The article now lists key advanced features, adds clearer enable/disable instructions, and refines guidance for EDR in block mode, file blocking, and duplicate device records. Metadata was also updated.

What Defender admins need to know

Admins have clearer configuration guidance and explicitly stated EDR in block mode prerequisites: active Microsoft Defender Antivirus and cloud-based protection.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure advanced features in Defender for Endpoint

DependingYou can configure the following Defender for Endpoint advanced features depending on the Microsoft security products that you use, you can integrate Defender for Endpoint with the advanced features described in this article.your environment.

Enable advanced features

To enable or disable an advanced feature in the Microsoft Defender portal:

  1. Go to the Microsoft Defender portal and sign in.

  2. In the navigation pane, select Settings > Endpoints > Advanced features.

Restrict correlation to within scoped device groups

The scoped device group correlation setting can be used for scenarios where local SOC operations would like to limit alert correlations only to device groups that they can access. When thisthe scoped device group correlation setting is turned on, an incident composed of alerts that cross-device groups areis no longer considered a single incident. The local SOC can then take action on the incident because they have access to one of the device groups involved. However, global SOC sees several different incidents by device group instead of one incident. We don't recommend turning on this setting unless doing so outweighs the benefits of incident correlation across the entire organization.

Enable EDR in block mode

Endpoint detection and response (EDR) in block mode provides protection from malicious artifacts, even when Microsoft Defender Antivirus is running in passive mode. When EDR in block mode is turned on, it blocks malicious artifacts or behaviors that are detected on a device. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post breach.

Automatically resolve alerts

Turn on the auto-resolve alerts setting to automatically resolve alerts where no threats were found or where detected threats were remediated. If you don't want to have alerts auto resolved, you'll need to manually turn off the feature.

Configure allow or block file settings

Blocking is only available ifTo use this feature, your organization fulfillsmust meet these requirements:

  • Uses Microsoft Defender Antivirus asis the active antimalware solution and,solution.
  • The cloud-Cloud-based protection feature is enabledenabled.

The allow orThis feature lets you block file feature enables you to block potentially maliciousharmful files in your network. BlockingWhen you block a file will prevent it from being read, written, or executed onfile, devices in your organization.organization can't read, write, or run it.

To turn on Allow or block files on:files:

  1. In the Microsoft Defender portal, in the navigation pane, select Settings > Endpoints > General > Advanced features > Allow or block file.

  2. Toggle the setting between On and Off.

    a. :::image type="content" source="/defender/media/alloworblockfile.png" alt-text="The Endpoints screen" lightbox="/defender/media/alloworblockfile.png":::

  3. Select Save preferences at the bottom of the page.

  4. After turningyou turn on this feature, you can block files viafrom the Add Indicator tab on a file's profile page.

Hide potential duplicate device records

By enabling theTurn on this feature to hide potential duplicate device records feature,so you can ensure that you're seeingsee only the most accurate information about your devices by hiding potential duplicatedata for each device. Duplicates can happen for many reasons. For example, device records. There are different reasons duplicate device records might occur, for example, the device discovery capability in Microsoft Defender for Endpoint might scan your network and discoverfind a device that's is already onboarded or haswas recently been offboarded.

The hide potential duplicate device recordsThis feature identifies potential duplicate devices based on theirmatches duplicates by hostname and last seen time. The duplicate devices will be hiddenIt hides them from multiple experiences in the portal, such as, the Device Inventory, Microsoft Defender Vulnerability Management pages, and Public APIs for machine data, leaving thedata. The most accurate device record stays visible. However, the duplicates willDuplicates still be visibleappear in global search, advanced hunting, alerts, and incidents pages.

The hide potential duplicate device recordsThis setting is turned on by default and is appliedapplies tenant wide. If you don't want to hide potentialTo show duplicate device records, you'll need to manually turn off the feature.feature manually.

Configure custom network indicators

Turning on custom network indicators allows you to create indicators for IP addresses, domains, or URLs, which determine whether they'll be allowed or blocked based on your custom indicator list.

To use this feature, devices must be running Windows 10 version 1709 or later, or Windows 11.

For more information, see Overview of indicators.

Enable tamper protection

During some kinds of cyber attacks, bad actorsattackers might try to disableturn off security features, such asfeatures like antivirus protection,protection on your machines. Bad actors likedevices. They do this to disableaccess your security features to get easier access to your data, to install malware, or to otherwise exploit your data, identity,identity and devices. Tamper protection essentially locks Microsoft Defender Antivirus and preventsstops your security settings from being changed throughby apps andor other methods.

For more information, including how to configure tamper protection, see Protect security settings with tamper protection.

Configure Skype for Business integration

Enabling the Skype for Business integration gives you the ability to communicate with users using Skype for Business, email, or phone. This activationThe Skype for Business integration can be handy when you need to communicate with the user and mitigate risks.

Configure Microsoft Defender for Cloud Apps integration

Enabling this settingthe Microsoft Defender for Cloud Apps integration forwards Defender for Endpoint signals to Microsoft Defender for Cloud Apps to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Defender for Cloud Apps data.

For more information, see Microsoft Defender for Cloud Apps overview.

Configure web content filtering

Block access to websites containing unwanted content and track web activity across all domains. Before you deploy the Microsoft Defender for Endpoint security baseline, ensure network protection is in block mode. To specify the web content categories you want to block, create a web content filtering policy. Ensure you've network protection in block mode when deploying the Microsoft Defender for Endpoint security baseline.

Enable the unified audit log

Download quarantined files

Backup quarantined files in a secure and compliant location so they can be downloaded directly from quarantine. The Download file button willis always be available in the file page. ThisThe download quarantined files setting is turned on by default. Requirements for downloading quarantined files

Default to streamlined connectivity when onboarding devices in the Defender portal

The streamlined connectivityThis setting will setmakes streamlined connectivity the default onboarding package to streamlined connectivity for applicablesupported operating systems. You can still have the option to use the standard onboarding package withinpackage, but you need to select it from the drop-down on the onboarding page, but you must specifically select it in the drop-down.page.

Enable live response

Turn on this feature so that users with the appropriate permissions can start a live response session on devices.

For more information about role assignments,To assign roles for live response, see Create and manage roles.

Enable live response for servers

Enabling this feature allows you to run unsigned scripts in a live response session.

AutomaticConfigure automatic attack disruption

Automatic attack disruption disruptsstops attacks by automatically containing compromised assets that the attacker is using.controls. It limits lateral movement early on, thereby reducingearly, which reduces the overall impact ofcost and productivity loss from an attack, both on the associated costs and on loss of productivity. At the same time, it leaves securityattack. Security operations teams in completekeep full control of investigating, remediating,to investigate, fix issues, and bringingbring assets back online. For more information, see Automatic attack disruption in Microsoft Defender.

Share endpoint alerts with Microsoft Compliance Center

ThisThe endpoint alert sharing setting forwardssends endpoint security alerts and their triage status to the Microsoft Purview portal, allowing youportal. You can use these alerts to enhanceimprove insider risk management policies with alerts and remediateaddress internal risks before they cause harm. Forwarded data is processed and stored in the same location as your Office 365 data.

After configuringyou set up the Security policy violation indicatorspolicy indicators in the insider risk management settings, Defender for Endpoint shares alerts will be shared with insider risk management for applicable users.

Configure the Microsoft Intune connection

You can integrate Defender for Endpoint can be integrated with Microsoft Intune to enable device risk-based conditional access. When you configure Conditional Access, you'll be able to share Defender for Endpoint shares device informationdata with Intune, enhancing policy enforcement.Intune to help enforce policies.

This feature is only available if you'verequires the following prerequisites:following:

  • A licensed tenant for Enterprise Mobility + Security E3, and Windows E5 (or Microsoft 365 Enterprise E5)
  • An active Microsoft Intune environment, with Intune-managed Windows devices Microsoft Entra joined.

Enable preview features

Learn about new features in the Defender for Endpoint preview release.

Try upcoming features by turning on the preview experience. You'll have access to upcoming features, which you can provide feedback on to help improve the overall experience before features are generally available.

If you already have preview features turned on, manage your settings from the main Defender XDR settings.

For more information, see Microsoft Defender XDR preview features

Configure Endpoint Attack Notifications

Endpoint Attack Notifications enablelet Microsoft to actively hunt for critical threats to be prioritized based on urgency and impact overin your endpoint data. Threats are ranked by urgency and impact.

For proactive hunting across the full scope of Microsoft Defender XDR, including threats that span email, collaboration, identity, cloud applications,apps, and endpoints, get started with Microsoft Defender Experts about Microsoft Defender Experts..

Related content