Skip to content

Commit 1d99f5a

Browse files
authored
Merge branch 'main' into docs-editor/ios-whatsnew-1733920733
2 parents c92241f + b3155fe commit 1d99f5a

File tree

1 file changed

+11
-8
lines changed

1 file changed

+11
-8
lines changed

defender-endpoint/indicator-ip-domain.md

Lines changed: 11 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: conceptual
1616
ms.subservice:
1717
search.appverid: met150
18-
ms.date: 10/23/2024
18+
ms.date: 12/11/2024
1919
---
2020

2121
# Create indicators for IPs and URLs/domains
@@ -37,7 +37,7 @@ By creating indicators for IPs and URLs or domains, you can now allow or block I
3737
To block malicious IPs/URLs (as determined by Microsoft), Defender for Endpoint can use:
3838

3939
- Windows Defender SmartScreen for Microsoft browsers
40-
- Network Protection for non-Microsoft browsers, or calls made outside of a browser
40+
- Network protection for non-Microsoft browsers, or calls made outside of a browser
4141

4242
The threat-intelligence data set to block malicious IPs/URLs is managed by Microsoft.
4343

@@ -65,15 +65,15 @@ It's important to understand the following prerequisites prior to creating indic
6565

6666
### Microsoft Defender Antivirus version requirements
6767

68-
This feature is available if your organization uses [Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-windows) (in active mode)
68+
- Your organization uses [Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-windows). Microsoft Defender Antivirus must be in active mode for non-Microsoft browsers. With Microsoft browsers, like Edge, Microsoft Defender Antivirus can be in active or passive mode.
6969

70-
[Behavior Monitoring](/defender-endpoint/behavior-monitor) is enabled
70+
- [Behavior Monitoring](/defender-endpoint/behavior-monitor) is enabled.
7171

72-
[Cloud-based protection](/windows/security/threat-protection/microsoft-defender-antivirus/deploy-manage-report-microsoft-defender-antivirus) is turned on.
72+
- [Cloud-based protection](/windows/security/threat-protection/microsoft-defender-antivirus/deploy-manage-report-microsoft-defender-antivirus) is turned on.
7373

74-
[Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is functional
74+
- [Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is turned on.
7575

76-
The antimalware client version must be `4.18.1906.x` or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates).
76+
- The antimalware client version must be `4.18.1906.x` or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates).
7777

7878
### Network Protection requirements
7979

@@ -142,7 +142,9 @@ Policy conflict handling for domains/URLs/IP addresses differ from policy confli
142142
In the case where multiple different action types are set on the same indicator (for example, **block**, **warn**, and **allow**, action types set for Microsoft.com), the order those action types would take effect is:
143143

144144
1. Allow
145+
145146
2. Warn
147+
146148
3. Block
147149

148150
"Allow" overrides "warn," which overrides "block", as follows: `Allow` > `Warn` > `Block`. Therefore, in the previous example, `Microsoft.com` would be allowed.
@@ -175,6 +177,7 @@ The result is that categories 1-4 are all blocked. This is illustrated in the fo
175177
3. Select **Add item**.
176178

177179
4. Specify the following details:
180+
178181
- Indicator - Specify the entity details and define the expiration of the indicator.
179182
- Action - Specify the action to be taken and provide a description.
180183
- Scope - Define the scope of the machine group.
@@ -192,4 +195,4 @@ The result is that categories 1-4 are all blocked. This is illustrated in the fo
192195
- [Manage indicators](indicator-manage.md)
193196
- [Exclusions for Microsoft Defender for Endpoint and Microsoft Defender Antivirus](defender-endpoint-antivirus-exclusions.md)
194197

195-
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
198+
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)