
Explanation:
Box 1: Microsoft Defender Firewall
Block users from transferring files over FTP.
Microsoft Defender Firewall settings include MdmStore/Global/DisableStatefulFtp, which could be used to disable stateful FTP.
Box 2: Microsoft Defender Exploit Guard
Prevent Microsoft Office applications from launching child processes.
Attack surface reduction rules in the Microsoft Defender.
These rules include: Block all Office applications from creating child processes Note: Attack surface reduction rule merge behavior is as follows:
Attack surface reduction rules from the following profiles are evaluated for each device the rules apply to:
Devices > Configuration policy > Endpoint protection profile > *Microsoft Defender Exploit Guard* > Attack Surface Reduction Endpoint security > Attack surface reduction policy > Attack surface reduction rules Endpoint security > Security baselines > Microsoft Defender for Endpoint Baseline > Attack Surface Reduction Rules.
Reference:
https://docs.microsoft.com/en-us/intune/endpoint-protection-windows-10