STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) Discovery Mode must be set to All Devices.

DISA Rule

SV-275997r1119727_rule

Vulnerability Number

V-275997

Group Title

SRG-APP-000279

Rule Version

MSDE-00-001400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints. Select which devices to use for Standard discovery (under Discovery setup).
2. Select "All devices (recommended)".

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Device Discovery. Select which devices to use for Standard discovery (under Discovery setup).
2. Verify "All devices (recommended)" is selected.

If the slide bar for "All devices (recommended)" is not selected, this is a finding.

Vulnerability Number

V-275997

Documentable

False

Rule Version

MSDE-00-001400

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Device Discovery. Select which devices to use for Standard discovery (under Discovery setup).
2. Verify "All devices (recommended)" is selected.

If the slide bar for "All devices (recommended)" is not selected, this is a finding.

Check Content Reference

M

Target Key

5693