STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) Discovery Mode must enable Log4j2 detection.

DISA Rule

SV-275996r1119726_rule

Vulnerability Number

V-275996

Group Title

SRG-APP-000279

Rule Version

MSDE-00-001350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Discovery setup (under Discovery setup).
2. Select Standard discovery.
3. Select the slide bar for "Enable Log4j2 detection".

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Device Discovery >> Discovery setup (under Discovery setup).
2. Verify Standard discovery is selected and the slide bar for "Enable Log4j2 detection" is selected.

If the slide bar for "Enable Log4j2 detection" is not selected, this is a finding.

Vulnerability Number

V-275996

Documentable

False

Rule Version

MSDE-00-001350

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Device Discovery >> Discovery setup (under Discovery setup).
2. Verify Standard discovery is selected and the slide bar for "Enable Log4j2 detection" is selected.

If the slide bar for "Enable Log4j2 detection" is not selected, this is a finding.

Check Content Reference

M

Target Key

5693