STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must enable Full remediation for Device groups.

DISA Rule

SV-275998r1119728_rule

Vulnerability Number

V-275998

Group Title

SRG-APP-000279

Rule Version

MSDE-00-001450

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Device groups (under Permissions).
2. Enter each Device group and enable Full remediation.

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Device groups (under Permissions).
2. For all device groups: Verify the remediation column is set to Full remediation.

If the remediation column for all Device groups is not set to "Full remediation", this is a finding.

Vulnerability Number

V-275998

Documentable

False

Rule Version

MSDE-00-001450

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Device groups (under Permissions).
2. For all device groups: Verify the remediation column is set to Full remediation.

If the remediation column for all Device groups is not set to "Full remediation", this is a finding.

Check Content Reference

M

Target Key

5693