Skip to content

Commit 236fa97

Browse files
committed
Update tvm-block-vuln-apps.md
1 parent c6d122e commit 236fa97

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-vulnerability-management/tvm-block-vuln-apps.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ ms.date: 12/05/2024
2424
- [Microsoft Defender XDR](/defender-xdr)
2525
- [Microsoft Defender for Servers Plan 2](/azure/defender-for-cloud/plan-defender-for-servers-select-plan)
2626

27-
Remediating vulnerabilities takes time and can be dependent on the responsibilities and resources of the IT team. Security administrators can temporarily reduce the risk of a vulnerability by taking immediate action to block all currently known vulnerable versions of an application until the remediation request is completed. The block option gives your IT teams time to patch an application without worrying your security administrators that the vulnerabilities will be exploited.
27+
Remediating vulnerabilities takes time and can be dependent on the responsibilities and resources of the IT team. Security administrators can temporarily reduce the risk of a vulnerability by taking immediate action to block all currently known vulnerable versions of an application until the remediation request is completed. The block option gives your IT teams time to patch an application without worrying your security administrators about the vulnerabilities.
2828

2929
While taking the remediation steps suggested by a security recommendation, security administrators can perform a mitigation action and block vulnerable versions of an application. File indicators of compromise (IOC)s are created for each of the executable files that belong to vulnerable versions of that application. Microsoft Defender Antivirus then enforces blocks on the devices that are in the specified scope.
3030

@@ -135,7 +135,7 @@ When users try to access a blocked application, they receive a message informing
135135
For applications where the warn mitigation option was applied, users receive a message informing them that the application was blocked by their organization. The user can bypass the block for subsequent launches, by choosing "Allow". This allow action is only temporary, and the application is blocked again after a while.
136136

137137
> [!NOTE]
138-
> If your organization has deployed the `DisableLocalAdminMerge` group policy, you could experience instances where allowing an application does not take effect.
138+
> If your organization has deployed the `DisableLocalAdminMerge` group policy, you could experience instances where allowing an application doesn't take effect.
139139
140140
## End-user updating blocked applications
141141

0 commit comments

Comments
 (0)