Skip to content

Commit 421ffa3

Browse files
authored
Update indicator-ip-domain.md
1 parent 3ada348 commit 421ffa3

File tree

1 file changed

+4
-7
lines changed

1 file changed

+4
-7
lines changed

defender-endpoint/indicator-ip-domain.md

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -49,22 +49,19 @@ You can block malicious IPs/URLs through the settings page or by machine groups,
4949
### Supported operating systems
5050

5151
- Windows 11
52-
5352
- Windows 10, version 1709 or later
5453
- Windows Server 2022
5554
- Windows Server 2019
5655
- Windows Server 2016 running [Defender for Endpoint modern unified solution](/defender-endpoint/configure-server-endpoints) (requires installation through MSI)
57-
5856
- Windows Server 2012 R2 running [Defender for Endpoint modern unified solution](/defender-endpoint/configure-server-endpoints) (requires installation through MSI)
59-
6057
- macOS
6158
- Linux
6259
- iOS
6360
- Android
6461

6562
## Before you begin
6663

67-
It's important to understand the following prerequisites prior to creating indicators for IPS, URLs, or domains:
64+
It's important to understand the following prerequisites prior to creating indicators for IPS, URLs, or domains.
6865

6966
### Microsoft Defender Antivirus version requirements
7067

@@ -76,15 +73,15 @@ This feature is available if your organization uses [Microsoft Defender Antiviru
7673

7774
[Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is functional
7875

79-
The *Antimalware client version* must be 4.18.1906.x or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates)
76+
The antimalware client version must be `4.18.1906.x` or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates).
8077

8178
### Network Protection requirements
8279

8380
URL/IP allow and block requires that the Microsoft Defender for Endpoint component _Network Protection_ is enabled in **block mode**. For more information on Network Protection and configuration instructions, see [Enable network protection](enable-network-protection.md).
8481

8582
### Custom network indicators requirements
8683

87-
To start blocking IP addresses and/or URL's, turn on "**Custom network indicators"** feature in **Microsoft Defender XDR** (in the Microsoft Defender portal), go to **Settings** > **Endpoints** > **General** > **Advanced features**. For more information, see [Advanced features](advanced-features.md).
84+
To start blocking IP addresses and/or URL's, turn on "**Custom network indicators"** feature in the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Endpoints** > **General** > **Advanced features**. For more information, see [Advanced features](advanced-features.md).
8885

8986
For support of indicators on iOS, see [Microsoft Defender for Endpoint on iOS](ios-configure-features.md#configure-custom-indicators).
9087

@@ -145,7 +142,7 @@ In the case where multiple different action types are set on the same indicator
145142
2. Warn
146143
3. Block
147144

148-
_Allow_ overrides _warn_ which overrides _block_: Allow > Warn > Block. Therefore, in the above example, Microsoft.com would be allowed.
145+
_Allow_ overrides _warn_ which overrides _block_: Allow > Warn > Block. Therefore, in the above example, `Microsoft.com` would be allowed.
149146

150147
### Defender for Cloud Apps Indicators
151148

0 commit comments

Comments
 (0)