In this blog post Microsoft Defender for Endpoint Settings You Need to Configure, we will explain why switching the platform on is only the first step. Many businesses assume they are protected because their devices appear in the Defender portal, while important prevention rules remain disabled, alerts go nowhere and risky devices can still access company data.

At a high level, Microsoft Defender for Endpoint protects laptops, desktops and servers by monitoring what happens on them. It combines antivirus protection with endpoint detection and response, often shortened to EDR, which looks for suspicious behaviour rather than relying only on a list of known viruses.

Information from each device is analysed using Microsoft’s cloud security services. When Defender sees behaviour that resembles ransomware, credential theft or another attack, it can alert your team, isolate the device and help investigate what happened.

Turning it on does not mean the job is finished

Onboarding connects a device to Defender so it can report security information. It does not automatically confirm that every protection setting is suitable for your organisation.

This is where many deployments stop. The IT provider confirms that devices are visible, closes the project and assumes Microsoft’s default settings will handle everything else.

A well-configured deployment should answer five business questions:

  • Are all company devices covered?
  • Can users or malware disable protection?
  • Are common attack techniques being blocked?
  • Will someone respond when Defender detects a threat?
  • Can a compromised device still access Microsoft 365 data?

1. Confirm every device is reporting correctly

Start with coverage, not advanced settings. Defender cannot protect a device that has never been onboarded, has stopped communicating or was forgotten during a hardware rollout.

Compare the Defender device inventory with Microsoft Intune, which manages and secures company devices, as well as your asset register and server list. Pay particular attention to remote laptops, shared computers, older servers, newly acquired businesses and devices used by contractors.

Assign an owner to investigate devices that have not reported recently. A monthly coverage report should show management how many devices are protected, inactive or missing.

This basic check closes blind spots and gives you more reliable security and compliance reporting.

2. Create one central source for security policies

Defender settings can be controlled through Microsoft Intune, the Defender portal, Group Policy and other management tools. Using several methods without a clear plan can create conflicting policies and unpredictable results.

For most Microsoft 365 environments, Intune is the practical place to manage endpoint security. Defender security settings management can also apply policies to supported devices that are not fully enrolled in Intune.

Build separate policies for antivirus, firewall, endpoint detection and response, attack surface reduction and device controls. Use clear names, document who owns each policy and avoid changing the same setting in multiple places.

This reduces troubleshooting time and makes it easier to prove which controls apply during an audit.

3. Protect Defender from being switched off

Attackers often try to disable security tools before deploying ransomware or stealing data. Users with excessive local permissions can also change settings accidentally while troubleshooting software.

Enable tamper protection, which prevents unauthorised changes to important Defender settings. You should also enable cloud-delivered protection so suspicious files and behaviours can be checked against current Microsoft threat information.

Review antivirus exclusions at the same time. Broad exclusions such as an entire drive, user profile or application folder can create a convenient hiding place for malware.

Every exclusion should have a documented business reason, an owner and a review date. If nobody can explain why it exists, it should not remain indefinitely.

4. Configure attack surface reduction rules carefully

Attack surface reduction rules, usually called ASR rules, block software behaviour commonly used during cyber attacks. Examples include an Office document starting another program, a script downloading malicious software or an application attempting to steal stored credentials.

These controls can stop an attack before traditional antivirus identifies a malicious file. They also support several goals within the Essential Eight, the Australian government’s cybersecurity framework that many organisations use as a security baseline.

Do not enable every rule in blocking mode across the entire business on day one. A safer rollout is:

  1. Apply the rules in audit mode so Defender records what would have been blocked.
  2. Review the results for two to four weeks.
  3. Test exceptions for genuine business applications.
  4. Move a small pilot group into blocking mode.
  5. Expand the policy in stages after confirming business applications still work.

For more detail on hardening Windows devices, see our guide to securing Windows 11 devices with Defender XDR.

5. Turn on protection beyond downloaded files

Modern attacks do not always begin with an obvious infected attachment. A user may follow a phishing link, a legitimate application may connect to an attacker-controlled server or malicious code may run entirely in memory.

Enable network protection to help block connections from applications to malicious and suspicious internet destinations. Where appropriate, configure web content filtering to restrict categories that introduce unacceptable security, compliance or productivity risks.

Controlled folder access can also protect important folders from unauthorised changes made by untrusted applications. This is useful against ransomware, but it should be tested because some older business applications may require carefully scoped exceptions.

6. Use device risk to control access

An alert has limited value if a compromised laptop can continue opening email, SharePoint files and other company systems. Connecting Defender with Intune and Microsoft Entra Conditional Access allows the device’s security status to influence whether access is granted.

For example, a high-risk device can be marked non-compliant and prevented from accessing company information until it has been investigated. This contains potential damage without waiting for someone to read an email alert.

Begin with reporting and a pilot group before enforcing access restrictions. You need an emergency process for executives, travelling employees and other users who may be blocked at an inconvenient time.

7. Configure alerts, responsibilities and automation

Defender can generate valuable alerts, but those alerts need an owner. Sending everything to a generic mailbox that nobody checks is not an incident response process.

Define who reviews new incidents, what severity requires immediate action and when external help should be contacted. Use role-based access control so staff and service providers receive only the permissions needed for their responsibilities.

Where your licence supports it, configure automated investigation and remediation. This allows Defender to investigate related evidence and take approved actions, such as quarantining a malicious file, without waiting for every task to be completed manually.

Automation should be monitored rather than blindly trusted. Review completed investigations, failed actions and unresolved incidents as part of a regular security meeting.

8. Act on vulnerability information

Defender can identify outdated software, missing updates and configuration weaknesses across monitored devices. This turns patching from a monthly guessing exercise into a risk-based process.

Prioritise vulnerabilities that are actively being exploited, affect internet-facing systems or appear across a large number of devices. Assign each remediation task to a named owner and track how long serious issues remain open.

This is particularly useful for Essential 8 readiness because patching applications and operating systems are two core mitigation strategies. Defender provides valuable evidence and prioritisation, although it does not make an organisation compliant by itself.

A practical example

Consider a 180-person professional services company that had Defender enabled across most Windows laptops. The portal was receiving data, but alerts went to an unmonitored mailbox, several remote devices were missing and no attack surface reduction rules had been deployed.

A staged review identified an old finance workflow that would conflict with one ASR rule. The workflow was updated, the rule was piloted and then moved into blocking mode. High-risk devices were also prevented from accessing Microsoft 365 until reviewed.

The business did not need to buy another security dashboard. It needed to configure and operate the capability it already owned, reducing both its exposure and the likelihood of paying for overlapping tools. This is why Defender for Business is often enough for small and mid-sized companies when it is managed properly.

What good looks like after the first 30 days

Within the first month, you should have a verified device inventory, central security policies, tamper protection, tested prevention rules and a documented alert process. Management should also receive a short report covering device coverage, major vulnerabilities, active incidents and overdue actions.

The goal is not to switch on every available feature. It is to create a reliable security service that prevents common attacks, highlights real risk and helps your team respond quickly.

CloudProInc brings more than 20 years of enterprise IT experience to practical Microsoft security projects. As a Melbourne-based Microsoft Partner and Wiz Security Integrator, we help organisations across Australia configure Defender, Intune, Microsoft 365 and cloud security controls without turning the project into a giant consulting exercise.

If Defender is already switched on but you are not sure what it is actually blocking, who is watching the alerts or whether every device is covered, we are happy to take a look โ€” no strings attached.


Discover more from CPI Consulting

Subscribe to get the latest posts sent to your email.