Microsoft Defender for Endpoint STIG Checklist (Version 1, Release 2)
19 items · Security · Medium difficulty · 4 hours
Implement MDE STIG controls to secure endpoints and meet DoD requirements.
-
Review MDE STIG documentation
Read Version 1, Release 2 and supporting resources before making changes.
-
Inventory endpoints for MDE eligibility
List OS versions, device roles, and management status (managed/standalone).
-
Confirm licensing and tenant enrollment
Verify required MDE licenses and tenant configuration before onboarding.
-
Onboard devices to Microsoft Defender for Endpoint
Use the recommended deployment method for servers and endpoints (MDM, local installers, or scripts).
-
Enable Endpoint Detection and Response (EDR) in block mode
Activate EDR to detect and block advanced threats per STIG guidance.
-
Configure automated investigation and remediation
Turn on automated remediation to reduce manual triage time.
-
Enable Microsoft Defender Antivirus real-time protection
Ensure real-time scanning is active and tamper protection prevents changes.
-
Configure attack surface reduction (ASR) rules
Enable recommended ASR rules to block common exploit vectors.
-
Enable cloud-delivered protection and sample submission
Allow cloud heuristics and safe sample submission to improve detections.
-
Configure MDE policies in Intune or Group Policy
Apply centralized policies for antivirus, EDR, ASR, and exclusions.
-
Configure antivirus exclusions per STIG guidelines
Limit exclusions to validated cases and document each justification.
-
Add approved exclusions for apps and paths
Only add exclusions with evidence and minimal scope (process, path, or extension).
-
Document exclusions and justification
Record who approved the exclusion, why, and when it will be reviewed.
-
Enable tamper protection
Prevent unauthorized changes to MDE settings from local or remote agents.
-
Verify telemetry and central logging to MDE console
Confirm events, alerts, and logs are forwarded to the Defender portal.
-
Integrate with Microsoft Entra ID and Conditional Access
Ensure device identity and access controls align with security policies.
-
Run STIG compliance scan and remediate findings
Execute compliance checks and address any non-compliant configurations.
-
Document configurations and change history
Keep a record of setting changes, approvals, and version updates.
-
Schedule regular reviews and update cadence
Set periodic reviews for policies, exclusions, and STIG changes.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.