Skillplan M365 Checklist
2026-07-20 19:28
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 11 of 17
Defender for Endpoint
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Enable Tamper Protection for every onboarded device.
Not Fulfilled
Fulfilled
Accepted
Enable all Attack Surface Reduction (ASR) rules in audit mode first; promote to block after monitoring.
Not Fulfilled
Fulfilled
Accepted
Onboard every Windows 10/11 and Server 2019+ device into Defender for Endpoint within 7 days of deployment.
Not Fulfilled
Fulfilled
Accepted
Enable Automatic Investigation and Response with 'Full - remediate threats automatically' for low-risk machines.
Not Fulfilled
Fulfilled
Accepted
Configure Web content filtering for known malicious and policy-violating categories.
Not Fulfilled
Fulfilled
Accepted
Enable Device discovery to catch unmanaged devices on the same network as managed assets.
Not Fulfilled
Fulfilled
Accepted
Require Microsoft Defender Antivirus cloud-delivered protection on every device.
Not Fulfilled
Fulfilled
Accepted
Restrict AV exclusions to Microsoft-recommended guidance; reject ad-hoc business exclusions without review.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →