Skip to content

Commit 2b84945

Browse files
committed
Learn Editor: Update indicators-overview.md
1 parent e6d48fe commit 2b84945

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

defender-endpoint/indicators-overview.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -119,6 +119,11 @@ When your security team creates a new indicator (IoC), the following actions are
119119
> [!NOTE]
120120
> Using Warn mode prompts users with a warning if they open a risky app or website. The prompt doesn't block them from allowing the application or website to run, but you can provide a custom message and links to a company page that describes appropriate usage of the app. Users can still bypass the warning and continue to use the app if necessary. For more information, see [Govern apps discovered by Microsoft Defender for Endpoint](/defender-cloud-apps/mde-govern).
121121
122+
> [!NOTE]
123+
> For Warn action, To receive the toast notification to be able to bypass the IoC, make sure the **“Files or activities are blocked”** option is enabled under **Virus & Threat Protection notifications**. The corresponding registry key should be set as follows: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Defender Security Center\Virus and threat protection\FilesBlockedNotificationDisabled = 0.
124+
>
125+
> More details see **[Windows Security app settings](https://support.microsoft.com/windows/windows-security-app-settings-1ec98620-4e41-4b6b-b055-3c4bb115d4ee#bkmk_notifications)**.
126+
122127
You can create an indicator for:
123128

124129
- [Files](indicator-file.md)

0 commit comments

Comments
 (0)