Skip to content
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune

How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune

Written By Anoop C Nair
Last Updated June 25, 2026
Posted In Intune
SHARE

How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune. Attack Surface Reduction (ASR) policies in Microsoft Intune is very important to protect devices from different types of cyber threats. It block suspicious activities, such as unknown scripts or malicious files, that could harm your system. These rules reduce the chances of attackers exploiting weaknesses in your devices.

Sometimes it is important to delete an ASR policy from Intune for example, when the policy is outdated, no longer needed, or replaced with a new one. Removing unused or duplicate policies helps keep your Intune environment clean and easier to manage.

You can easily delete the ASR policy through Intune admin center. Once deleted, the policy will no longer apply to your managed devices. However, it may take a short time for the changes to reflect on all systems. Make sure to verify that no important protection rules are lost before deleting the policy.

Deleting an Attack Surface Reduction (ASR) policy in Intune helps IT admins by keeping the environment organized and efficient. When a policy becomes outdated, duplicated, or replaced with a new version, removing it prevents confusion and ensures that only relevant and updated security policies are applied.

Patch My PC
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune - Fig.1
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune – Fig.1

How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune

Deleting an Attack Surface Reduction (ASR) policy in Intune helps organizations by improving security management and operational efficiency. When outdated or duplicate policies are removed, it ensures that only the most relevant and updated rules are enforced across all devices.

Steps
Sign in to https://intune.microsoft.com with your admin account
Select Endpoint Security to access security policies
Choose Attack Surface Reduction to view all existing ASR policies.
Click on the specific ASR policy you want to remove.
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune – Table 1

Here i select the Block executable files from running unless they meet a prevalence, age, or trusted list criterion policy. This rule blocks the following file types from launching unless they meet prevalence or age criteria, or they’re in a trusted list or an exclusion list: Executable files (such as .exe, .dll, or .scr).

How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune - Fig.2
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune – Fig.2

Check Policy Status Before Deletion

After selecting the ASR policy, click the Delete button. Before confirming, review the Device and User check-in status to understand where the policy is currently applied. The status may show details such as “Succeeded to 2 devices,” indicating that the policy has been successfully deployed to two managed devices.

  • This helps ensure that you are aware of its impact before removing the policy from Intune.
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune - Fig.3
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune – Fig.3

Confirm Policy Deletion

After clicking the Delete button, a confirmation pop-up window will appear. It will notify you that this action will permanently delete the selected profile. If you are sure about removing the policy, click OK to proceed. If you want to review the settings again, click Cancel to stop the deletion process.

How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune - Fig.4
How to Delete Attack Surface Reduction ASR Policy from Microsoft Intune – Fig.4

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read