Microsoft Defender for Endpoint
Endpoint protection

Device control policies in Microsoft Defender for Endpoint

In brief

The ComputerSid description now identifies the Microsoft Entra group object ID as the supported Entra identifier, replacing the broader reference to an Entra object or Object ID.

What Defender admins need to know

Administrators configuring device control policies have clearer guidance on which Entra identifier to use.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Device control policies in Microsoft Defender for Endpoint

| Option | If type is AuditDenied | - 0: nothing
- 1: show notification
- 2: send event
- 3: show notification and send event | | AccessMask | Defines the access | See the following section Understand mask access | | Sid | Local user SID or user SID group, or the SID of the Microsoft Entra object or the Object ID. It defines whether to apply this policy over a specific user or user group. One entry can have a maximum of one SID and an entry without any SID means to apply the policy over the device. | SID | | ComputerSid | Local computer SID or computer SID group, or the SID of the Microsoft Entra group object or the Object Id.ID. It defines whether to apply this policy over a specific device or device group. One entry can have a maximum of one ComputerSID and an entry without any ComputerSID means to apply the policy over the device. If you want to apply an Entry to a specific user and specific device, add both SID and ComputerSID into the same Entry. Microsoft Entra device object IDs currently aren't supported. | SID | | Parameters | Condition for an entry, such as network condition. | Can add groups (nondevice types) or even put parameters into parameters. For more information, see the advanced conditions section (in this article). |

Understand mask access (Windows)