Microsoft announced that its endpoint security platform, Defender for Endpoint, is now generally available with tamper protection for all devices connected to the platform.
See also: Microsoft Defender for Office 365: Teams users will be able to report phishing messages

This default set of settings provides better protection against advanced and emerging threats, including ransomware.
“From now on, enabling breach protection will be included in the tenant’s built-in security measures,” Microsoft explains, with other default settings coming soon.
Microsoft Defender is a cybersecurity tool that helps protect your devices and data from online threats, such as viruses, malware, and phishing attacks. It's built into the Windows operating system and provides real-time protection against these threats. Additionally, Microsoft Defender can also help you recover your data if your device is lost or stolen.
Administrators can enable cloud-based protection until the company releases more updates that include default protection settings.
Last year, the company began enabling tamper protection for all new customers with Defender for Endpoint Plan 2 or Microsoft 365 E5 licenses .
The company announced that in September it will enable Ampere protection by default on all Microsoft Defender for Endpoint (MDE) systems. This will protect Microsoft Defender Antivirus with safe default values and prevent any changes to security settings.
See also: Microsoft Defender: Falsely detects Win32/Hive.ZY in Google Chrome applications

“As an additional measure to ensure the security of our customers, breach protection will now be automatically enabled for all existing customers who have not already disabled it in the Microsoft 365 Defender portal,” said Josh Bregman, Principal Product Manager at Microsoft.
This is achieved by blocking other applications from changing settings for real-time and cloud-delivered protection. This includes Defender components such as IOfficeAntivirus (IOAV), which handles the detection of suspicious files downloaded from the Internet.
If you haven't yet set up tamper protection in your corporate environment, don't worry – Microsoft 365 Defender will soon send you a notification to let you know that the feature is about to be enabled.
However, administrators can also change the default protection settings or choose to opt out:
- Navigate to the Microsoft 365 Defender portal and sign in.
- Go to Settings > Endpoints > Advanced features.
- Make sure Tamper protection is enabled, then select Save Preferences. Don't leave this page yet.
- Disable Tamper protection by clicking the toggle, then select Save Preferences.
See also: Microsoft Defender: Better blocks ransomware in Windows 11
Microsoft 365 administrators can use Security Manager for Defender for Endpoint or create a profile in Microsoft Endpoint Manager to exclude certain devices on the network from breachif there is an application compatibility issue.
