Skip to main content

Attack Surface Reduction

Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2) - v3.7

CMMC Control Mapping Matrix

NameValue
Basics
NameWin - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2) - v3.7
DescriptionDO NOT ASSIGN THIS POLICY WITHOUT VALIDATING VIA AUDIT MODE FIRST!
https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-deployment-operationalize
Profile typeSettings catalog
CategoryAttack surface reduction
Policy typeAttack Surface Reduction Rules
Platform supportedWindows 10 and later
CreatedThursday, February 26, 2026 2:33:51 AM
Last modifiedThursday, February 26, 2026 2:33:51 AM
Scope tagsDefault
Table 1. Basics - Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2) - v3.7
NameValue
Defender
Attack Surface Reduction Rules
Block Adobe Reader from creating child processesBlock
Block process creations originating from PSExec and WMI commandsWarn
Block execution of potentially obfuscated scriptsWarn
Block persistence through WMI event subscriptionBlock
Block Win32 API calls from Office macrosBlock
Block Office applications from creating executable contentBlock
Block credential stealing from the Windows local security authority subsystemBlock
Block use of copied or impersonated system toolsBlock
Block executable files from running unless they meet a prevalence, age, or trusted list criterionAudit
Block JavaScript or VBScript from launching downloaded executable contentBlock
Block Office communication application from creating child processesWarn
Block Office applications from injecting code into other processesBlock
Block all Office applications from creating child processesBlock
Block rebooting machine in Safe ModeAudit
Block untrusted and unsigned processes that run from USBBlock
Use advanced protection against ransomwareBlock
Block executable content from email client and webmailBlock
Block abuse of exploited vulnerable signed drivers (Device)Block
Enable Controlled Folder AccessAudit Mode
Table 2. Settings - Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2) - v3.7

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.