How to Configure Attack Surface Reduction Rules in Defender for Endpoint
Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.
Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child processes. Here is how to roll them out without breaking business applications.
Step 1: Understand the key rules
Commonly prioritized ASR rules include:
- Block all Office applications from creating child processes.
- Block Office applications from creating executable content.
- Block Office applications from injecting code into other processes.
- Block executable content from email client and webmail.
- Block JavaScript or VBScript from launching downloaded executable content.
- Block credential stealing from the Windows local security authority subsystem (lsass.exe).
- Block abuse of exploited vulnerable signed drivers.
- Block process creations originating from PSExec and WMI commands (test carefully).
- Use advanced protection against ransomware.
Step 2: Deploy in audit mode
Use Intune endpoint security policies (Attack surface reduction profiles) to set rules to Audit. Leave them for two to four weeks.
Step 3: Review audit events
In the Defender portal, review the ASR rules report or query DeviceEvents where ActionType starts with "Asr" to see which applications would be blocked.
Step 4: Add exclusions carefully
Exclude specific file paths or applications only where legitimate business processes are affected. Avoid broad exclusions.
Step 5: Switch to block mode
Move rules to Block in waves — starting with rules with no audit hits, then others. Consider Warn mode for some rules, letting users bypass with notice.
Step 6: Monitor
Track blocked events and user-reported issues.
Verify
Defender's configuration management shows ASR rule status per device. Aim for block mode on all high-value rules across all devices.
- Follina (May–June 2022): Office Documents That Ran Code Without Macros Incident Teardowns
- Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Attackers Adapt When You Block Macros CIO Briefings