INTUNE-009: Attack Surface Reduction rules configuration
- Plataforma
- Entra ID / M365
- Categoría
- Intune / Endpoint Management
- Severidad
- High
- Pilar de Zero Trust
- Devices (peso 3)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Attack Surface Reduction (ASR) rules in Microsoft Defender block common attack techniques such as obfuscated scripts, Office macro exploitation, and credential theft from LSASS. Without ASR rules configured and enforced, endpoints remain vulnerable to well-known attack patterns that commodity malware and adversaries routinely exploit. Properly configured ASR rules significantly reduce the attack surface of Windows endpoints.
Valor recomendado
All recommended ASR rules enabled in block mode; audit mode for newly deployed rules during testing
Remediación
Review the current ASR rule configuration in Intune endpoint security and enable all Microsoft-recommended rules in at least audit mode. After a monitoring period to identify false positives, transition rules to block mode starting with high-impact rules such as blocking Office applications from creating child processes and blocking credential theft from LSASS. Configure ASR rule exclusions sparingly and only for documented business-critical applications, monitoring the ASR events report for ongoing effectiveness.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- CM-7
- MITRE ATT&CK
- T1059