ASR Rules - Some won't apply
-
I know that there probably aren't too many folks on here using the full MS security platform but I figure it's worth checking in.
For the life of me, I can't get the below Attack Surface Reduction rules to apply, regardless of the method... Is there some sort of spell, incantation or sacred offering that must be performed for this to work?
As usual, Microsoft's "documentation" isn't exactly straightforward and direct. I tried configuring via the custom MEM OMA-URI method this morning, I'll have to wait until Monday to see if it's actually going to take this time. I've already got the same restrictions set via Endpoint Security with no success.
We're still in a hybrid AD scenario, so I could technically try to use GPO, but we're trying to do as much via Intune / cloud as possible.
Any known issues that folks have come across with this stuff?