PUA Protection

Alyse Hart 25 Reputation points
2024-01-10T21:04:41.1133333+00:00

I'm working to understand a few Secure Score Recommendations, and one recommendation that I have a few questions about is the "Turn on PUA protection in block mode" action.

I understand that by turning this on in an enterprise environment will help protect against the download of PUAs themselves, but

  • If an organization were to turn on this feature; but does that make Defender scan and retroactively remove any possible PUAs on a user device?
  • If this feature is turned on in block mode, does the protection also stop any possible side loaded applications, executables, etc.? (referring to the MediaArena malware and the way that some users have inadvertently downloaded a PUA when looking for PDF software.)
  • Does this protect the Intune Managed device or just PUAs downloaded in the Edge Browser?

Article: https://www.reddit.com/r/DefenderATP/comments/13cgiq0/mediaarena_unwanted_software_was_prevented/

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,456 questions
0 comments No comments
{count} vote

Accepted answer
  1. ZhoumingDuan-MSFT 8,840 Reputation points Microsoft Vendor
    2024-01-11T05:36:19.0166667+00:00

    @Alyse Hart, Thanks for posting in Q&A. From your description, I know you have a few questions about "Turn on PUA protection in block mode" action.

    For your problem, I have done some research, here is some information you can refer.

    1.If you turn on PUA protection in block mode, it does not make Defender scan and retroactively remove any possible PUAs on a user device. However, when configured in blocking mode, PUA files are moved to the quarantine.

    2.If this feature is turned on in block mode, it will help protect against the download of PUAs, including side loaded applications, executables and so on.

    3.This feature protects all devices that have Microsoft Defender Antivirus installed, including Intune Managed devices.

    Hope above information can help. If there is any update, feel free to let me know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Alyse Hart 25 Reputation points
    2024-01-12T12:24:09.5833333+00:00

    Thank you @ZhoumingDuan-MSFT This was tremendously helpful, just one last follow-up question; in the event of a False Positive, and the PUA is moved to quarantine, it can be released by an Administrator to the specific user, correct?