> For the complete documentation index, see [llms.txt](https://docs.realmjoin.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/device/security/restrict-or-release-code-execution.md).

# コード実行を制限または解除

### 説明

この runbook は、Microsoft Defender for Endpoint を介してデバイス上のコード実行を制限し、Microsoft によって署名されたコードのみが実行できるようにします。必要に応じて、既存の制限を解除することもできます。アクションがサービスに記録されるよう、短い理由を入力してください。

### 場所

デバイス → セキュリティ → コード実行の制限または解除

**Runbook の完全名**

rjgit-device\_security\_restrict-or-release-code-execution

### 詳細

| プロパティ    | 値                                  |
| -------- | ---------------------------------- |
| バージョン    | 1.0.1                              |
| 必要なモジュール | RealmJoin.RunbookHelper (>= 0.8.9) |
| スケジュール可能 | いいえ                                |

### アクセス許可

#### アプリケーションのアクセス許可

* **種類**: WindowsDefenderATP
  * Machine.Read.All
    * *aadDeviceId でフィルターされた /machines を使用して Microsoft Defender for Endpoint のマシンを検索します*
  * Machine.RestrictExecution
    * *マシンで restrictCodeExecution または unrestrictCodeExecution をトリガーします*

### パラメーター

#### DeviceId

対象デバイスのデバイス ID。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | はい                       |
| 既定値      |                          |
| 種類       | 文字列                      |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### 解除

「コード実行を制限する」（最終値: false）または「コード制限を解除する」（最終値: true）を、実行するアクションとして選択できます。false に設定すると、runbook は Microsoft Defender for Endpoint のデバイスでコード実行を制限します。true に設定すると、Microsoft Defender for Endpoint のデバイスで既存のコード実行制限を解除します。

| プロパティ   | 値     |
| ------- | ----- |
| 必須      | はい    |
| 既定値     | False |
| 種類      | ブール値  |
| ポータル表示名 | アクション |

**ポータルのオプション**

| ポータルオプション  | 値   |
| ---------- | --- |
| コード実行を制限する | いいえ |
| コード制限を解除する | はい  |

#### コメント

制限または解除アクションの短い理由。

| プロパティ   | 値                |
| ------- | ---------------- |
| 必須      | はい               |
| 既定値     | セキュリティ上のリスクの可能性。 |
| 種類      | 文字列              |
| ポータル表示名 | 制限または解除の理由       |

[Runbook Reference の概要に戻る](/ja/zi-dong-hua/runbooks/runbook-references.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/device/security/restrict-or-release-code-execution.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
