Device Control
- Microsoft Defender for Endpoint: Attack Surface Reduction
ASR-Regeln, Windows-Firewall, Web Protection, SmartScreen & Enhanced Phishing Protection, Controlled Folder Access, Credential Guard und Device Control – wie du mit Defender for Endpoint die Angriffsfläche systematisch reduzierst: GUIDs, PowerShell, Intune-Profile und der bewährte Audit-zu-Block-Rollout.