← Microsoft 365 Certified: Endpoint Administrator Associate
AZURE · objective · 18% of the exam
Protect devices — Microsoft 365 Certified: Endpoint Administrator Associate
The official AZURE documentation our Protect devices practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Allowed - Removable drives are scanned during any type of scan. This is the recommended configuration.
-
Microsoft — ASR rules overview - Microsoft Defender for Endpoint | Microsoft Learn
Per-ASR rule exclusions : Assign different exclusions selectively to different ASR rules.
-
Microsoft — Plan your ASR rules deployment - Microsoft Defender for Endpoint | Microsoft Learn
If you already defined rings for phased rollout of Windows updates, you can likely use those same rings to deploy ASR rules.
-
Microsoft — Monitor ASR rule activity - Microsoft Defender for Endpoint | Microsoft Learn
select ASR events from the Event group section, and then select Apply . The default timeframe is 1 week , but you can also select
-
Opting in to Microsoft Update means that protection updates can be delivered to devices (via Microsoft Update) even if you have set WSUS to override
-
Microsoft — Manage and monitor your ASR rules deployment - Microsoft Defender for Endpoint | Microsoft Learn
Depending on the size of your organization, reviews might be hourly, daily, or continuously.
-
Microsoft — Overview of endpoint detection and response capabilities - Microsoft Defender for Endpoint | Microsoft Learn
Defender for Endpoint detection is not intended to be an auditing or logging solution that records every operation or activity that happens on a given