Skip to content
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules

Written By Anoop C Nair
Last Updated November 11, 2025
Posted In Intune
SHARE

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules. The “Block executables that impersonate or are copies of system tools and binaries” ASR rule in Intune is a security policy that helps you to stop malicious programs that try to act like trusted Windows system tools.

Your Windows computer has many important system tools, such as cmd.exe and PowerShell.exe. These are built-in and safe. However, hackers sometimes create fake versions of these tool files that appear identical but actually contain harmful code. For example, they might make a fake “PowerShell.exe” and use it to attack your computer.

This Intune ASR rule helps you stop those fake files. It checks if a program pretending to be a system tool is real or not. If it’s a fake copy, the rule blocks it from running, keeping your device safe. This ASR rule is very helpful for IT admins and organisations because it adds an extra layer of protection against advanced cyberattacks that are often hard to detect.

For IT admins, it reduces the risk of malware spreading through fake system files. They don’t have to manually check every executable. Intune automatically blocks any program pretending to be a Windows tool. This saves time, and keeps endpoint security consistent across all managed devices.

Patch My PC

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules

For the organization, it strengthens overall security by preventing attackers from using trusted Windows utilities for malicious purposes. This rule helps maintain a clean, trusted environment where only genuine system files can run, keeping both devices and company data safe.

  • To block the use of copied or impersonated system tools, start by signing in to the Microsoft Intune Admin Portal using your admin credentials.
  • Once logged in, go to Endpoint security and select Attack surface reduction.
  • From there, click on Create Policy to set up a new ASR rule.
PlatformProfile
WindowsAttack Surface Reduction Rules
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Table 1
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.1
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.1

Basic Settings – Block Use of Copied or Impersonated System Tools

In the Basics tab, provide the necessary details for your ASR policy. These details help identify the purpose of the policy clearly within the Intune console. Giving a meaningful name and description makes it easier for IT admins to manage, track, and update the rule as part of the organization’s endpoint protection strategy.

  • Name: Block use of copied or impersonated system tools.
  • Description: Block use of copied or impersonated system tools using Intune.
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.2
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.2

Configure Rule Settings – Block Use of Copied or Impersonated System Tools

In this section, choose how the ASR rule should behave on managed devices. You will see the following options available for configuration: To ensure maximum protection, select Block, which prevents fake or unauthorized copies of system tools from running on devices managed through Intune.

Policy NameAvailable Options
Block Use of Copied or Impersonated System ToolsNot Configured
Off (Default)
Block
Audit
Warn
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Table 2
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.3
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.3

Set Policy to Audit Mode

In this policy, the Audit mode is selected to monitor how the rule behaves before fully enforcing it. When in audit mode, the policy does not block any executables but instead records all detection events where copied or impersonated system tools are identified.

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.4
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.4

Scope Tag – Default

The Scope Tag defines which admins or groups can view and manage a specific policy in Intune. In this case, the default tag named “Default” is automatically applied. This tag is used when no custom or user-defined scope tags are assigned.

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.5
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.5

Assign Policy to a Group – HTMD CPC Test

In the Assignments section of the policy, the target group HTMD CPC Test is selected. Assigning the policy to this specific group ensures that the ASR rule applies only to the devices included in that group. This allows IT admins to test and monitor the policy’s behavior in a controlled environment before deploying it widely across the organization.

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.6
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.6

Review + Create Step

This final step allows you to ensure that everything is accurate before deployment. Once you’ve reviewed and confirmed the details, click Create to finalize and deploy the policy. The screenshot below helps you to show more details.

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.7
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.7

Policy Creation and Assignment Confirmation

After completing the setup, you will see two confirmation notifications in the Intune portal. The first message, “Create policy – Block use of copied or impersonated system tools has successfully been created,” confirms that the policy has been created successfully. The second message, “Save assignments – Group assignments for Block use of copied or impersonated system tools has been successfully saved,” indicates that the policy has been correctly assigned to the selected group.

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.8
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.8

Device and User Check-In Status

After deploying the policy, the Device and User Check-In Status shows the results of how the policy was applied across targeted devices. The device and user check in status is shown below.

  • Succeeded: 1
  • Not applicable: 0
  • In Progress: 0
  • Error: 0
  • Conflict: 0
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.9
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.9

Verify Policy Deployment in Event Logs

To confirm that the Block use of copied or impersonated system tools policy has been applied successfully, you can check the device’s Event Viewer. Navigate to the following path: Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin

Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules - Fig.10
Block Executables Impersonating or Copying System Tools and Binaries using Intune ASR Rules – Fig.10

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read