STIGQter STIGQter: STIG Summary:

Microsoft Defender for Endpoint Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-272882r1119408_ruleMicrosoft Defender for Endpoint (MDE) must alert administrators on policy violations defined for endpoints.
SV-272886r1119409_ruleRoles for use with Microsoft Defender for Endpoint (MDE) must be configured within Entra ID.
SV-272887r1156554_ruleMicrosoft Defender for Endpoint (MDE) must be configured for a least privilege model by implementing Unified Role-Based Access Control (RBAC).
SV-272888r1119411_ruleMicrosoft Defender for Endpoint (MDE) must enable Endpoint Detection and Response (EDR) in block mode.
SV-272889r1119412_ruleMicrosoft Defender for Endpoint (MDE) must be connected to a central log server.
SV-275979r1119709_ruleMicrosoft Defender for Endpoint (MDE) must enable Automatically Resolve Alerts.
SV-275980r1119710_ruleMicrosoft Defender for Endpoint (MDE) must enable Allow or block file.
SV-275981r1119731_ruleMicrosoft Defender for Endpoint (MDE) must enable Hide potential duplicate device records.
SV-275982r1119712_ruleMicrosoft Defender for Endpoint (MDE) must enable Custom network indicators.
SV-275983r1119713_ruleMicrosoft Defender for Endpoint (MDE) must enable Tamper protection.
SV-275984r1119714_ruleMicrosoft Defender for Endpoint (MDE) must enable Show user details.
SV-275985r1119715_ruleMicrosoft Defender for Endpoint (MDE) must enable Microsoft Defender for Cloud Apps.
SV-275986r1119716_ruleMicrosoft Defender for Endpoint (MDE) must enable Web content filtering.
SV-275987r1119717_ruleMicrosoft Defender for Endpoint (MDE) must enable Device discovery.
SV-275988r1119718_ruleMicrosoft Defender for Endpoint (MDE) must enable Download quarantined files.
SV-275989r1119719_ruleMicrosoft Defender for Endpoint (MDE) must enable Live Response.
SV-275990r1119720_ruleMicrosoft Defender for Endpoint (MDE) must enable Live Response for Servers.
SV-275991r1119721_ruleMicrosoft Defender for Endpoint (MDE) must enable Share endpoint alerts with Microsoft Compliance Center.
SV-275992r1119722_ruleMicrosoft Defender for Endpoint (MDE) must enable Microsoft Intune connection.
SV-275993r1119723_ruleMicrosoft Defender for Endpoint (MDE) must enable Authenticated telemetry.
SV-275994r1119724_ruleMicrosoft Defender for Endpoint (MDE) must enable File Content Analysis.
SV-275995r1119725_ruleMicrosoft Defender for Endpoint (MDE) must enable Memory Content Analysis.
SV-275996r1119726_ruleMicrosoft Defender for Endpoint (MDE) Discovery Mode must enable Log4j2 detection.
SV-275997r1119727_ruleMicrosoft Defender for Endpoint (MDE) Discovery Mode must be set to All Devices.
SV-275998r1119728_ruleMicrosoft Defender for Endpoint (MDE) must enable Full remediation for Device groups.