Microsoft Defender for Endpoint: onboarding, antivirus modes, ASR rules and exclusions
Administrator and technician work in Microsoft Defender for Endpoint: onboarding in rings and proving devices report, reading sensor health, how Microsoft Defender Antivirus runs in active, passive or disabled state alongside other antivirus, EDR in block mode, tamper protection, rolling out attack surface reduction rules from audit to block, device groups with role-based access, and governing exclusions and indicators. Alert triage and response actions are covered in 'Defender for Endpoint alerts: triage basics'.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Microsoft Defender for Endpoint
Skills you'll practise
- Onboard devices in rings and verify them with the device inventory and a detection test
- Interpret Inactive, Impaired communications and No sensor data states and choose the next check
- Predict whether Microsoft Defender Antivirus runs active, passive or disabled and what that means for ASR rules and EDR in block mode
- Explain what tamper protection locks and how to make an approved change to a protected setting
- Plan an ASR rule rollout from Audit to Block, distinguishing standard protection rules from others
- Place devices in ranked device groups and decide between alert suppression, exclusions and indicators
Course outline
- 1.Microsoft Defender for Endpoint administrationVideo · 3 min
- 2.Onboarding and sensor healthLesson · 16 min
- 3.Antivirus modes, EDR in block mode and tamper protectionLesson · 17 min
- 4.ASR rules, device groups, exclusions and indicatorsLesson · 17 min
- 5.Microsoft Defender for Endpoint: onboarding, antivirus modes, ASR rules and exclusions: knowledge checkKnowledge check · 22 questions
- 6.Final exam11 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Microsoft Defender for Endpoint (overview and licensing options)
- Microsoft Learn: Onboard devices to Microsoft Defender for Endpoint (ring-based deployment, exit criteria)
- Microsoft Learn: Run a detection test on a device recently onboarded to Defender for Endpoint
- Microsoft Learn: Fix unhealthy sensors in Microsoft Defender for Endpoint
- Microsoft Learn: Microsoft Defender Antivirus compatibility with other security products (active, passive, disabled)
- Microsoft Learn: Endpoint detection and response (EDR) in block mode
- Microsoft Learn: Cloud protection and Microsoft Defender Antivirus
- Microsoft Learn: Tamper protection overview
- Microsoft Learn: Attack surface reduction (ASR) rules overview (modes, requirements, exclusions)
- Microsoft Learn: ASR rules deployment guide (plan, test, enable, manage)
- Microsoft Learn: Overview of exclusions and indicators in Microsoft Defender for Endpoint
- Microsoft Learn: Create and manage device groups in Microsoft Defender for Endpoint
- Microsoft Learn: Automation levels in automated investigation and remediation
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.