Is your feature request related to a problem? Please describe.
Windows Exploit Protection settings can be modified by end users through the Windows Security interface, even without local administrator rights. Users can add or modify Exploit Protection configurations, potentially weakening device security and creating configuration drift from an organization's intended security posture. Only deletion of existing entries is restricted to Administrators.
Describe the solution you'd like
Add and enforce the Disallow Exploit Protection Override setting (Windows Defender Security Center section) in the OpenIntuneBaseline. This prevents local users from making changes in the Windows Security Exploit Protection settings area and ensures centrally managed Exploit Protection configurations remain enforced.
Configure the setting as:
(Enable) Local users cannot make changes in the exploit protection settings area.
Describe alternatives you've considered
None. The goal is not to centrally manage Exploit Protection settings across all devices, but rather to prevent non-Administrators from being able to easily modify them through the Windows Security GUI.
Additional context
Testing confirmed that enabling Disallow Exploit Protection Override prevents local users from adding or modifying Exploit Protection settings through Windows Security.
When enabled, the Exploit Protection configuration interface becomes grayed out and users are presented with a "This setting is managed by your administrator" message, providing a clear indication that the setting is intentionally managed by policy.
The absence of this setting from common baselines and benchmarks is surprising given that non-administrative users can otherwise modify these settings. This policy only restricts the GUI. Applications, installers, and administrators can still configure Exploit Protection programmatically when required, preserving application compatibility while preventing unauthorized user changes.
Is your feature request related to a problem? Please describe.
Windows Exploit Protection settings can be modified by end users through the Windows Security interface, even without local administrator rights. Users can add or modify Exploit Protection configurations, potentially weakening device security and creating configuration drift from an organization's intended security posture. Only deletion of existing entries is restricted to Administrators.
Describe the solution you'd like
Add and enforce the Disallow Exploit Protection Override setting (Windows Defender Security Center section) in the OpenIntuneBaseline. This prevents local users from making changes in the Windows Security Exploit Protection settings area and ensures centrally managed Exploit Protection configurations remain enforced.
Configure the setting as:
(Enable) Local users cannot make changes in the exploit protection settings area.
Describe alternatives you've considered
None. The goal is not to centrally manage Exploit Protection settings across all devices, but rather to prevent non-Administrators from being able to easily modify them through the Windows Security GUI.
Additional context
Testing confirmed that enabling Disallow Exploit Protection Override prevents local users from adding or modifying Exploit Protection settings through Windows Security.
When enabled, the Exploit Protection configuration interface becomes grayed out and users are presented with a "This setting is managed by your administrator" message, providing a clear indication that the setting is intentionally managed by policy.
The absence of this setting from common baselines and benchmarks is surprising given that non-administrative users can otherwise modify these settings. This policy only restricts the GUI. Applications, installers, and administrators can still configure Exploit Protection programmatically when required, preserving application compatibility while preventing unauthorized user changes.