office application creating child process exclusion ASR

Guillaume AMGAR 6 Reputation points
2023-02-17T09:21:05.2233333+00:00

hi

we activated in block mode after audit the ASR rule "Block all office application from creating child process"

But exclusions does not seems to work (for testing)

1

In deed we work with Factset software that add a plugin in Excel that inject data in Excel but they are all blocked

2023-02-17 10_07_24-Window

2023-02-17 10_07_42-Window

Even excel does not open when launching the Factset plugin

Factset is well know legitimate software its so strange that MS does not have a whitelist but anyway, exclusion are not working at all

thanks for, your help

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,784 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,551 Reputation points MVP
    2023-02-18T06:08:34.8166667+00:00

    Try removing the * after factset\ . Check if the exclusions are actually applying on the machine. Get-mpprefence run with admin privileges should get you the list.

    0 comments No comments

  2. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-02-20T01:43:46.0666667+00:00

    @Guillaume AMGAR, Thanks for posting in Q&A.

    Based on my research, it seems the asterisk replaces a single folder. For our situation, I think we can change the value to C:\Program Files (x86)\Factset*.exe. Here is a link with more details for your reference:

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/configure-extension-file-exclusions-microsoft-defender-antivirus?view=o365-worldwide#use-wildcards-in-the-file-name-and-folder-path-or-extension-exclusion-lists

    Meanwhile, I notice per-rule exclusions cannot be added to the existing policy. As it is currently implemented, in order to configure per-rule exclusions, you must create a new policy in MEM to replace the existing policy. Please create a new policy with the new setting value to see if it works:

    User's image

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-deployment-test?view=o365-worldwide#configure-asr-rules-per-rule-exclusions

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.