MDM vs MicrosoftSense in Attack Surface Reduction

Nasty 0 Day doing the rounds at the moment

CVE-2023-36884 – Security Update Guide – Microsoft – Office and Windows HTML Remote Code Execution Vulnerability

Recommended route to fix this is the Attack Surface Reduction Rule  Block all Office applications from creating child processes 

Deploying this through Intune is Simple , but what about servers? Remember Intune only works with Windows Devices

ASR rules actually work for Servers IF they have been onboarded into Defender

Make sure the ASR policy Targets MicrosoftSense

Onboarded in MDE is MicrosoftSense

MDM is Intune

Items that work on MDR in ASR Attack surface reduction rules reference | Microsoft Learn

https://blog.mindcore.dk/2023/02/assign-asr-rules-to-your-non-enrolled-devices-through-microsoft-intune/
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...