ASR Policy "Not Applicable"

SMB 1 Reputation point
2022-10-12T18:26:15.25+00:00

Company has two (2) VMs hosted in Azure. These VMs use Windows Defender as their Antivirus solution and recently (2-3 months ago), Company's Secure Score has been negatively affected for Windows Defender metrics; applicable to the two VMs. Secure Score has dropped from 7x% to 5x%.

The remediation steps have suggested – 1. Ensure Windows Defender is enabled along with real-time protection, cloud delivery etc. 2. Create and apply ASR rules

Remediation step 1 above has been actioned manually on the VMs but the issue now lies with applying the ASR rules.

Steps taken thus far:

  1. Onboarded VMs to Intune using Pilot mode and the “MDE-Management” tag. VMs now appear in Intune.
  2. Created an AV Policy and applied to a group with the VMs as members
    a. AV Policy applied successfully
  3. Created an ASR Policy and applied to the group
    a. ASR Policy shows as “Not Applicable”

I require assistance in determining why the policy status is “Not Applicable” and measures that can be taken to rectify the issue.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
3,044 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,063 questions
{count} votes

8 answers

Sort by: Most helpful
  1. AdamSupel-9488 20 Reputation points
    2024-01-11T16:52:20.5466667+00:00

    Ok works now. That's what I did find in policy Block Webshell creation for Servers and set it to ‘Not Configured’
    need to investigate that, but in general without that setting works fine. Please confirm from your side.
    Regards Adam

    3 people found this answer helpful.

  2. Gianluca S-B 5 Reputation points
    2024-01-11T16:30:44.71+00:00

    Hello, I am having the same issue but on MDE-only Windows 10 workstations that are Hybrid AAD-joined (but not enrolled in Intune). I did everything that was needed, they look good in Intune as MDE, they're receiving the AV policy but not the ASR that shows as Not applicable. I have a small doubt about the cloud-delivered protection: there are two settings inside the policy settings in Intune\Endpoint Security\Antivirus: Allow Cloud Protection and Cloud Protection Level. They look the same as the ones that can be found under the Security baseline (called exactly cloud-delivered protection) ... however, when asking that to Copilot/Bing chat it said no, they're different level of protection :D. This is damn confusing and if so, I couldn't find cloud-delivered protection setting in the AV policy. This feature needs to be active for some, if not for all, ASR rules. Is anyone experiencing the same issue on simple Windows 10 workstations that are MDE-managed? Thank you!

    1 person found this answer helpful.
    0 comments No comments

  3. AdamSupel-9488 20 Reputation points
    2024-01-11T16:54:28.3066667+00:00

    Ok works now. That's what I did find in policy Block Webshell creation for Servers and set it to ‘Not Configured’  need to investigate that, but in general without that setting works fine. Please confirm from your side. Regards Adam

    1 person found this answer helpful.

  4. Lu Dai-MSFT 28,486 Reputation points
    2022-10-14T01:35:47.797+00:00

    @SMB Thanks for your update.

    Based on my understanding, intune can manage windows client and can't manage windows server. In the following intune article, the ASR policy is applied to windows 10 or windows 11.
    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-profile-settings

    The server you can see in intune portal is synced from Windows Defender. However, it is still not managed by intune. So, this ASR policy shows "Not Applicable".

    Hope my answer clear something.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  5. Limitless Technology 44,686 Reputation points
    2022-10-14T07:35:19.807+00:00

    Hello there,

    Can you see any ASR keys in the below location HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\Rules

    Can you run this Powershell command get-mppreference and see any ASR listed here?

    I have also found this article, There is a known issue with the applicability of Attack Surface Reduction on Server OS versions which is marked as compliant without any actual enforcement. Currently, there is no ETA for when this will be fixed.

    More info here https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-attack-surface-reduction?view=o365-worldwide#microsoft-endpoint-configuration-manager

    -------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.