Updated: April 20, 2022 (September 30, 2019)

  Analyst Report

Managing Defender Exploit Guard Attack Surface Reduction

My Atlas / Analyst Reports

1,626 wordsTime to read: 9 min
Michael Cherry by
Michael Cherry

Michael analyzed and wrote about Microsoft's operating systems, including the Windows client OS, as well as compliance and governance. Michael... more

  • Windows 10 Defender Exploit Guard Attack Surface Reduction can help protect devices from malware.
  • The best Attack Surface Reduction management options may require Windows Enterprise E5 licenses.
  • Attack Surface Reduction requires significant ongoing monitoring because it may block useful applications.

Windows Defender Exploit Guard (Exploit Guard) is part of the Windows 10 Defender suite of security-related components built into Windows 10 Enterprise and Education editions. Prior to Windows 10 version 1709, Exploit Guard was named Device Guard. (For an overview of where Exploit Guard fits in the Windows 10 Defender software suite, see “Understanding Defender Device, Exploit, and Credential Guard and Application Control”.)

Attack Surface Reduction (ASR) is a main component of Exploit Guard. ASR reduces both the number of attack vectors (places where malware targets the software running on devices) and blocks the common methods that malware uses to compromise the OS or applications. Since application developers often exploit these same methods to deliver application functionality, managing ASR requires substantial ongoing monitoring and configuration tuning.

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now