This post has been de-listed
It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.
So Defender for Business is included in Business Premium licenses now and we want to configure it for customers, which has Business Premium.
I've ran a set up test policies on ourselfes to see if there are any issues. I've noticed certain Attack Surfaces Reduction policies prevent opening certain PNGs in Outlook and certain progams could not run their updaters from Windows tmp directories. So I turned off the options that were causing the issue.
However, that is not ideal. I would rather get an alert and/or create an exlcusion.
- I don't see any alerts for these events in the Security portal unde Endpoint.
- Cannot find a way to create pre-emptive exclusions for hashes/paths etc. in Security or MEM
Googling and reading Microsoft docs felt like these feature are only in Defender for Endpoint Plan 2.
Some direction or clarification would be highly apreciated.
Subreddit
Post Details
- Posted
- 2 years ago
- Reddit URL
- View post on reddit.com
- External URL
- reddit.com/r/DefenderATP...