In order to migrate from McAfee to Microsoft Defender for Endpoint successfully and mitigate known errors please refer to the instructions below,
1. Should follow the instructions and the phases defined in the article below in order to complete the migration process
Migrate from McAfee to Microsoft Defender for Endpoint | Microsoft Docs
2. Should use Audit mode for evaluation
Note: It is recommended to use audit mode to evaluate how attack surface reduction rules would affect your organization if they were enabled. Run all rules in audit mode first so you can understand how they affect your line-of-business applications. Many line-of-business applications are written with limited security concerns, and they might perform tasks in ways that seem similar to malware. By monitoring audit data and adding exclusions for necessary applications, you can deploy attack surface reduction rules without reducing productivity.
3. Usually Attack surface reduction blocks the execution of .exe file using the "Block executable files from running unless they meet a prevalence, age, or trusted list criterion," rule
4. Should refer to the article below in order to Exclude the affected files and folders from ASR rules
Enable attack surface reduction rules | Microsoft Docs
Note: Please refer to Attack surface reduction frequently asked questions (FAQ) | Microsoft Docs for more info on ASR
Comments
0 comments
Please sign in to leave a comment.