Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (Audit Mode) - v3.1 #173
Answered
by
markpartridge212
markpartridge212
asked this question in
Windows
-
|
Hi there this audit mode where would I find the audit logs to go through for audit mode or what is the purpose of the audit mode. I presume it would be to check the impact it would have on production devices if using the non audit mode but i cant seem to find any audit logs. Thanks in advance. |
Beta Was this translation helpful? Give feedback.
Answered by
markpartridge212
Jan 31, 2026
Replies: 1 comment 1 reply
-
|
If you go to the Security Portal, Reports, ASR then you can see what has been running but would be blocked if the rules were enforced. Then you can make any exceptions you need to in the block policy before enabling. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Thanks for the response much appreciated