EDR in block mode should be enabled or in passive mode for it to function correctly with the full automated remediation capabilities of Microsoft Defender XDR. EDR in block mode provides a crucial layer of protection for Microsoft Defender Antivirus, and while it's most beneficial when MDE is running in passive mode, it is necessary for automatic attack disruption to work effectively. Reference: https://learn.microsoft.com/en-us/defender-xdr/configure-attack-disruption