STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must enable Endpoint Detection and Response (EDR) in block mode.

DISA Rule

SV-272888r1119411_rule

Vulnerability Number

V-272888

Group Title

SRG-APP-000246

Rule Version

MSDE-00-000400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General).
2. Set the slide bar for "Enable EDR in block mode" to "On".

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General).
2. Verify the slide bar for "Enable EDR in block mode" is set to "On".

If the slide bar for "Enable EDR in block mode" is not set to "On", this is a finding.

Vulnerability Number

V-272888

Documentable

False

Rule Version

MSDE-00-000400

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Advanced features (under General).
2. Verify the slide bar for "Enable EDR in block mode" is set to "On".

If the slide bar for "Enable EDR in block mode" is not set to "On", this is a finding.

Check Content Reference

M

Target Key

5693