Microsoft 365How-To & HardeningRetrospectives

How to Configure Attack Surface Reduction Rules in Defender for Endpoint

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.

Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child processes. Here is how to roll them out without breaking business applications.

Step 1: Understand the key rules

Commonly prioritized ASR rules include:

  • Block all Office applications from creating child processes.
  • Block Office applications from creating executable content.
  • Block Office applications from injecting code into other processes.
  • Block executable content from email client and webmail.
  • Block JavaScript or VBScript from launching downloaded executable content.
  • Block credential stealing from the Windows local security authority subsystem (lsass.exe).
  • Block abuse of exploited vulnerable signed drivers.
  • Block process creations originating from PSExec and WMI commands (test carefully).
  • Use advanced protection against ransomware.

Step 2: Deploy in audit mode

Use Intune endpoint security policies (Attack surface reduction profiles) to set rules to Audit. Leave them for two to four weeks.

Step 3: Review audit events

In the Defender portal, review the ASR rules report or query DeviceEvents where ActionType starts with "Asr" to see which applications would be blocked.

Step 4: Add exclusions carefully

Exclude specific file paths or applications only where legitimate business processes are affected. Avoid broad exclusions.

Step 5: Switch to block mode

Move rules to Block in waves — starting with rules with no audit hits, then others. Consider Warn mode for some rules, letting users bypass with notice.

Step 6: Monitor

Track blocked events and user-reported issues.

Verify

Defender's configuration management shows ASR rule status per device. Aim for block mode on all high-value rules across all devices.

attack surface reduction rulesFollina2022

More on this story