Microsoft Defender for Endpoint Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates ✎ 1
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 1
- V-272887 Medium checkfix Microsoft Defender for Endpoint (MDE) must be configured for a least privilege model by implementing Unified Role-Based Access Control (RBAC).
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- MSDE-00-000100
- Vuln IDs
-
- V-272882
- Rule IDs
-
- SV-272882r1119408_rule
Checks: C-76973r1119211_chk
Access the MDE portal as a user with at least a Security Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts. 2. For each defined Notification rule: - Click on the rule and select "Edit" to enter the "Update notification rule" screen. - Verify the notification settings are configured as defined by the authorizing official (AO). - Verify the Recipient Emails are assigned as defined by the AO. 3. Click "Cancel". 4. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities. 5. For each defined notification rule: - Click on the rule and select "Edit" to enter the "Update notification rule" screen. - Verify the notification settings are configured as defined by the AO. - Verify the Recipient Emails are assigned as defined by the AO. 6. Click "Cancel". If Settings >> Endpoints >> Email notifications (under Permissions) >> Alerts does not display rules as defined by the AO, this is a finding. If Settings >> Endpoints >> Email notifications (under Permissions) >> Vulnerabilities does not display rules as defined by the AO, this is a finding. When selecting each rule individually, if the Notification Settings and Recipient Emails are not as defined by the AO, this is a finding.
Fix: F-76878r1119212_fix
Access the MDE portal as a user with at least a Security Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts. 2. Click "+Add notification rule". 3. Enter Name, Notification settings, and Recipients as defined by the AO. 4. Click "Save". Repeat as necessary. 5. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities. 6. Click "+Add notification rule". 7. Enter Name, Notification settings, and Recipients as defined by the AO. 8. Click "Save". Repeat as necessary.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- MSDE-00-000300
- Vuln IDs
-
- V-272886
- Rule IDs
-
- SV-272886r1119409_rule
Checks: C-76977r1119292_chk
Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles. 1. Select Manage >> Roles and administrators. Click on the "MDE Administrator" role. 2. Under "Active assignments" ensure one or more authorizing official (AO)-approved users are assigned to this role. This role is a top-level administrator within MDE. Note: A custom defined, AO-approved role may be created and used in lieu of the built-in MDE Administrator role. If one or more AO-approved users have not been assigned to the security administrator (or equivalent AO-approved) role, this is a finding. 1. Return to the Entra ID portal home and select Manage >> Groups. Click the number next to "Total Groups". 2. Ensure one or more custom roles have been defined as subordinate roles for MDE administration. The structure of various subordinate groups is to be defined by the AO. 3. Click on each of these groups and ensure one or more users have been assigned. If one or more subordinate groups do not exist, this is a finding. If one or more users do not exist in these subordinate groups, this is a finding.
Fix: F-76882r1119293_fix
Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles and users/groups. 1. Select Manage >> Roles and administrators. 2. Click on the "Security Administrator" role ,then click "+Add assignments". 3. Under "Select Member(s)" add AO-approved users for this role. This role is a top-level administrator within MDE. Note: A custom defined, AO-approved role may be created and used in lieu of the built-in "MDE Administrator" role. 4. Return to the Entra ID portal home and select Manage >> Groups. Click "New group". 5. Define at least one sub-level group for MDE administration as defined by the AO and assign users(s) to these groups.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- MSDE-00-000350
- Vuln IDs
-
- V-272887
- Rule IDs
-
- SV-272887r1156554_rule
Checks: C-76978r1156552_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Microsoft Defender XDR >> Permissions and Roles. 2. For each defined role: - Click the role to enter the edit role screen. - Verify the Permissions are configured as defined by the authorizing official (AO). - Verify the appropriate user groups are assigned as defined by the AO. - Click "Cancel". If Settings >> Microsoft Defender XDR >> Permissions and Roles does not display roles as defined by the AO, this is a finding. When selecting each role individually, if the permissions and user groups are not as defined by the AO, this is a finding.
Fix: F-76883r1156553_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Microsoft Defender XDR >> Permissions and Roles. 2. Select "+Add role". 3. Enter a Role Name, select "Permissions" as defined by the AO, and then click "Next". 4. Select the appropriate group as defined in MSDE-00-000300.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001094
- Version
- MSDE-00-000400
- Vuln IDs
-
- V-272888
- Rule IDs
-
- SV-272888r1119411_rule
Checks: C-76979r1119365_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Enable EDR in block mode" is set to "On". If the slide bar for "Enable EDR in block mode" is not set to "On", this is a finding.
Fix: F-76884r1119299_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Enable EDR in block mode" to "On".
- RMF Control
- AU-4
- Severity
- H
- CCI
- CCI-001851
- Version
- MSDE-00-000450
- Vuln IDs
-
- V-272889
- Rule IDs
-
- SV-272889r1119412_rule
Checks: C-76980r1119301_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Microsoft Sentinel. 2. Under "Workspaces", verify a Sentinel Workspace has been assigned. If a Sentinel Workspace has not been assigned, this is a finding. If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.
Fix: F-76885r1119367_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the MDE portal select Settings >> Microsoft Sentinel. 2. Under Workspaces connect a Sentinel Workspace.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000500
- Vuln IDs
-
- V-275979
- Rule IDs
-
- SV-275979r1119709_rule
Checks: C-80117r1119303_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Automatically Resolve Alerts" to "On".
Fix: F-80022r1119304_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Automatically Resolve Alerts" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000550
- Vuln IDs
-
- V-275980
- Rule IDs
-
- SV-275980r1119710_rule
Checks: C-80118r1119306_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Allow or block file" is set to "On". If the slide bar for "Allow or block file" is not set to "On", this is a finding.
Fix: F-80023r1119307_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Allow or block file" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000600
- Vuln IDs
-
- V-275981
- Rule IDs
-
- SV-275981r1119731_rule
Checks: C-80119r1119369_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Hide potential duplicate device records" is set to "On". If the slide bar for "Hide potential duplicate device records" is not set to "On", this is a finding.
Fix: F-80024r1119310_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Hide potential duplicate device records" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000650
- Vuln IDs
-
- V-275982
- Rule IDs
-
- SV-275982r1119712_rule
Checks: C-80120r1119371_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Custom network indicators" is set to "On". If the slide bar for "Custom network indicators" is not set to "On", this is a finding.
Fix: F-80025r1119313_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Custom network indicators" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000700
- Vuln IDs
-
- V-275983
- Rule IDs
-
- SV-275983r1119713_rule
Checks: C-80121r1119373_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Tamper protection" is set to "On". If the slide bar for "Tamper protection" is not set to "On", this is a finding.
Fix: F-80026r1119316_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Tamper protection" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000750
- Vuln IDs
-
- V-275984
- Rule IDs
-
- SV-275984r1119714_rule
Checks: C-80122r1119375_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Show user details" is set to "On". If the slide bar for "Show user details" is not set to "On", this is a finding.
Fix: F-80027r1119319_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Show user details" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000800
- Vuln IDs
-
- V-275985
- Rule IDs
-
- SV-275985r1119715_rule
Checks: C-80123r1119377_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Microsoft Defender for Cloud Apps" is set to "On". If the slide bar for "Microsoft Defender for Cloud Apps" is not set to "On", this is a finding.
Fix: F-80028r1119322_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Microsoft Defender for Cloud Apps" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000850
- Vuln IDs
-
- V-275986
- Rule IDs
-
- SV-275986r1119716_rule
Checks: C-80124r1119379_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Web content filtering" is set to "On". If the slide bar for "Web content filtering" is not set to "On", this is a finding.
Fix: F-80029r1119325_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Web content filtering" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000900
- Vuln IDs
-
- V-275987
- Rule IDs
-
- SV-275987r1119717_rule
Checks: C-80125r1119381_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Device discovery" is set to "On". If the slide bar for "Device discovery" is not set to "On", this is a finding.
Fix: F-80030r1119328_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Device discovery" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-000950
- Vuln IDs
-
- V-275988
- Rule IDs
-
- SV-275988r1119718_rule
Checks: C-80126r1119383_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Download quarantined files" is set to "On". If the slide bar for "Download quarantined files" is not set to "On", this is a finding.
Fix: F-80031r1119331_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Download quarantined files" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001000
- Vuln IDs
-
- V-275989
- Rule IDs
-
- SV-275989r1119719_rule
Checks: C-80127r1119385_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Live Response" is set to "On". If the slide bar for "Live Response" is not set to "On", this is a finding.
Fix: F-80032r1119334_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Live Response" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001050
- Vuln IDs
-
- V-275990
- Rule IDs
-
- SV-275990r1119720_rule
Checks: C-80128r1119387_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Live Response for Servers" is set to "On". If the slide bar for "Live Response for Servers" is not set to "On", this is a finding.
Fix: F-80033r1119337_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Live Response for Servers" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001100
- Vuln IDs
-
- V-275991
- Rule IDs
-
- SV-275991r1119721_rule
Checks: C-80129r1119389_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Share endpoint alerts with Microsoft Compliance Center" is set to "On". If the slide bar for "Share endpoint alerts with Microsoft Compliance Center" is not set to "On", this is a finding.
Fix: F-80034r1119340_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Share endpoint alerts with Microsoft Compliance Center" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001150
- Vuln IDs
-
- V-275992
- Rule IDs
-
- SV-275992r1119722_rule
Checks: C-80130r1119391_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Microsoft Intune connection" is set to "On". If the slide bar for "Microsoft Intune connection" is not set to "On", this is a finding.
Fix: F-80035r1119343_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Microsoft Intune connection" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001200
- Vuln IDs
-
- V-275993
- Rule IDs
-
- SV-275993r1119723_rule
Checks: C-80131r1119393_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Verify the slide bar for "Authenticated telemetry" is set to "On". If the slide bar for "Authenticated telemetry" is not set to "On", this is a finding.
Fix: F-80036r1119346_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General). 2. Set the slide bar for "Authenticated telemetry" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001250
- Vuln IDs
-
- V-275994
- Rule IDs
-
- SV-275994r1119724_rule
Checks: C-80132r1119395_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules). 2. Verify the slide bar for "File Content Analysis" is set to "On". If the slide bar for "File Content Analysis" is not set to "On", this is a finding.
Fix: F-80037r1119349_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules). 2. Set the slide bar for "File Content Analysis" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001300
- Vuln IDs
-
- V-275995
- Rule IDs
-
- SV-275995r1119725_rule
Checks: C-80133r1119397_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules). 2. Verify the slide bar for "Memory Content Analysis" is set to "On". If the slide bar for "Memory Content Analysis" is not set to "On", this is a finding.
Fix: F-80038r1119352_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules). 2. Set the slide bar for "Memory Content Analysis" to "On".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001350
- Vuln IDs
-
- V-275996
- Rule IDs
-
- SV-275996r1119726_rule
Checks: C-80134r1119399_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Device Discovery >> Discovery setup (under Discovery setup). 2. Verify Standard discovery is selected and the slide bar for "Enable Log4j2 detection" is selected. If the slide bar for "Enable Log4j2 detection" is not selected, this is a finding.
Fix: F-80039r1119400_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Discovery setup (under Discovery setup). 2. Select Standard discovery. 3. Select the slide bar for "Enable Log4j2 detection".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001400
- Vuln IDs
-
- V-275997
- Rule IDs
-
- SV-275997r1119727_rule
Checks: C-80135r1119402_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Device Discovery. Select which devices to use for Standard discovery (under Discovery setup). 2. Verify "All devices (recommended)" is selected. If the slide bar for "All devices (recommended)" is not selected, this is a finding.
Fix: F-80040r1119403_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints. Select which devices to use for Standard discovery (under Discovery setup). 2. Select "All devices (recommended)".
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- MSDE-00-001450
- Vuln IDs
-
- V-275998
- Rule IDs
-
- SV-275998r1119728_rule
Checks: C-80136r1119405_chk
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Device groups (under Permissions). 2. For all device groups: Verify the remediation column is set to Full remediation. If the remediation column for all Device groups is not set to "Full remediation", this is a finding.
Fix: F-80041r1119406_fix
Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Endpoints >> Device groups (under Permissions). 2. Enter each Device group and enable Full remediation.