ASR Policy "Not Applicable"

SMB 1 Reputation point
2022-10-12T18:26:15.25+00:00

Company has two (2) VMs hosted in Azure. These VMs use Windows Defender as their Antivirus solution and recently (2-3 months ago), Company's Secure Score has been negatively affected for Windows Defender metrics; applicable to the two VMs. Secure Score has dropped from 7x% to 5x%.

The remediation steps have suggested – 1. Ensure Windows Defender is enabled along with real-time protection, cloud delivery etc. 2. Create and apply ASR rules

Remediation step 1 above has been actioned manually on the VMs but the issue now lies with applying the ASR rules.

Steps taken thus far:

  1. Onboarded VMs to Intune using Pilot mode and the “MDE-Management” tag. VMs now appear in Intune.
  2. Created an AV Policy and applied to a group with the VMs as members
    a. AV Policy applied successfully
  3. Created an ASR Policy and applied to the group
    a. ASR Policy shows as “Not Applicable”

I require assistance in determining why the policy status is “Not Applicable” and measures that can be taken to rectify the issue.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
3,044 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,064 questions
{count} votes

8 answers

Sort by: Most helpful
  1. Mark Allen 1 Reputation point
    2023-12-27T10:32:13.7833333+00:00

    Hi

    I am experiencing exactly the same issue. I have targeted an AV policy and an ASR policy at a group which includes MDE managed servers. The AV policy is being successfully applied but the ASR policy is showing as "not applicable".

    I suspected it might be because we only had "Microsoft Defender for Endpoint Server" licenses in out tenancy so I got our CSP to add a Defender Endpoint P2 license but the problem still remains.

    Anyone able to offer advice/troubleshooting on this one?

    0 comments No comments

  2. AdamSupel-9488 20 Reputation points
    2024-01-11T15:26:38.24+00:00

    I've got a similar issue, misconfiguration. We have MDE-Management turned on for Servers, so in theory, Intune is not a part of the solution. All policies work fine besides ASR, so my question: is it possible to manage ASR policies via MDE or do we need to onboard servers to intune? in my case licensing type is direct onboarding by script, but servers via Arc and VM in Azure same story. Any solution or configuration advise ? /A

    0 comments No comments

  3. Quintin Schnuir 5 Reputation points
    2024-01-11T17:01:16.8+00:00

    Hi Adam, can you please explain step by step what you did to get it to work, so we can try doing the same thing. Thanx Quintin


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.