Windows Defender keeps losing ASRs deployed by Intune

AndAuf 16 Reputation points
2024-03-25T08:09:28.5733333+00:00

Hi all,

for the whole last week, I have a very strange and recurring problem.

Environment: Location EU0501, most devices HAADJ, some devices autopiloted entra only, Windows 10 and 11 on 22H2 or 23H2, Patchlevel 2024-02 or 2024-03 - so up to date. hybrid devices have a GPO which sets 5 ASRs, entra only get their ASRs from Intune "Endpoint Security | Attack Surface Reduction" and for hybrid devices they do not collide and exactly match.

So all devices looked like this all the time.

What happened the last week:

Defender for Endpoint portal suddenly told me, to enable all the ASRs on hundreds of devices. So after lots of syncing and looking and wondering, and confirming in Intune, that everything is set as it should be and status is success, the number of devices to remediate slowly dropped again. OK, some weird thing, fixed now.

Well... until the number dramatically raised again.

(That's just an example. All ASR look the same)

So I again started to look and found, that in Intune, I set the ASRs in "Endpoint Security | Security Baseline for Windows 10 and later", "Endpoint Security | Microsoft Defender for Endpoint Baseline" and "Endpoint Security | Attack Surface Reduction". But all were set exactly the same. So no conflict. Status for alle policies in Intune was "success". But as I don't need the same rules three times, I removed them from both the baselines. And it looked great. Devices synced, ASRs were shown and devices to remediate dropped again.

Until... they raised again

in all these troubleshooting, I also noticed, that it is definitely not just the number on Defender console. I can actually see it in my local powershell.

It should look like above. But the same powershell windows had it correctly and one hour later it return nothing. Starting another powershell as administrator, the list was complete. Until an hour later, when the same window returned nothing anymore. Some time later, the ASRs were listed again. For hybrid devices, the 5 ARs set by GPO are always listed correctly.

Screenshot on entra only device as administrator

And this happens to all devices in my tenant.

What is going on?!

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,758 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,756 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
333 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 43,126 Reputation points Microsoft Vendor
    2024-03-26T02:32:27.3433333+00:00

    @AndAuf, Thanks for posting in Q&A. From your description, I find ASR rules will disappear on lots of devices last week. And the ASR rules have not changed anything. things look strange. Could you check if any application bulk installed on the devices? Or if any other policies deployed to the devices?

    If the answer is yes, I suggest remove the app and the policy we deployed last week to see if the issue is resolved. if the answer is no, I suggest open case to look into the issue:

    https://learn.microsoft.com/en-us/mem/get-support

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.