A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint. The organization wants to block specific applications from launching on all Windows 10 and 11 devices across the organization. These applications are known to be used for non-business purposes and pose a security risk. Which feature should the administrator configure to achieve this?
- AControlled folder access
- BApplication control (Windows Defender Application Control)
- CAttack Surface Reduction (ASR) rules
- DExploit protection
Show answer & explanationAnswer & explanation
Correct answer: B. Application control (Windows Defender Application Control)
Application control, specifically Windows Defender Application Control (WDAC), is the feature designed to restrict which applications are allowed to run on devices. It works by creating policies that specify trusted applications, thereby blocking all others by default, or by explicitly blocking specific applications. ASR rules and Exploit protection aim to prevent specific attack behaviors, and Controlled folder access protects data from unauthorized access, none of which directly block specific applications from launching.
Why the other options are wrong
- A. Controlled folder access protects specific folders (e.g., Documents, Pictures) from being modified by untrusted applications, not for blocking the launch of applications themselves.
- C. ASR rules are designed to prevent specific attack behaviors (e.g., blocking executable content from email client, blocking credential stealing from OS memory), not to block specific applications by name or hash.
- D. Exploit protection aims to mitigate exploits against vulnerabilities in applications and services, it does not block the launch of entire applications.
Windows Defender Application Control (WDAC)
Windows Defender Application Control (WDAC) is a security feature that restricts which applications are allowed to run on Windows devices by creating policies that define trusted executables.
- Blocks untrusted applications from launching.
- Can be configured to whitelist (allow only specific apps) or blacklist (block specific apps).
- Rules can be based on publisher, file path, hash, or process.
- Critical for preventing unauthorized software and malware execution.
Memory trick: Remember, to 'Control' 'Applications' from 'Launching', use 'Application Control' to 'Block' them.