Microsoft Endpoint Administrator — Question 128
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender Antivirus on the computers.
You need to prevent users from disabling Microsoft Defender Antivirus.
What should you do?
Answer options
- A. From the Microsoft Intune admin center, create a security baseline.
- B. From the Microsoft 365 Defender portal, enable tamper protection.
- C. From the Microsoft Intune admin center, create an account protection policy.
- D. From the Microsoft Intune admin center, create an endpoint detection and response (EDR) policy.
Correct answer: B
Explanation
Enabling tamper protection in the Microsoft 365 Defender portal prevents users from disabling Microsoft Defender Antivirus, ensuring that the antivirus remains active and effective. The other options, such as creating a security baseline or account protection policy, do not specifically address the issue of preventing users from disabling the antivirus software.