Skip to content

Commit 429f28e

Browse files
committed
Learn Editor: Update device-control-policies.md
1 parent e273b74 commit 429f28e

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

defender-endpoint/device-control-policies.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -204,8 +204,12 @@ There are two types of entries: enforcement entries (Allow/Deny) and audit entr
204204

205205
### Audit entries
206206

207-
Audit events control the behavior when device control enforces a rule (allow/deny). Device control can display a notification to the end-user. The user gets a notification that contains the name of the device control policy and the name of the device. The notification appears once every hour after initial access is denied. Device control can also create an event that is available in Advanced Hunting.
207+
Audit events control the behavior when device control enforces a rule (allow/deny). Device control can display a notification to the end-user. The user gets a notification that contains the name of the device control policy and the name of the device. The notification appears once every hour after initial access is denied.
208208

209+
Device control can also create an event that is available in Advanced Hunting.
210+
211+
> [!IMPORTANT]
212+
> There is a limit of 300 events per device per day
209213
Audit entries are processed after the enforcement decision has been made. All corresponding audit entries are evaluated.
210214

211215
### Conditions

0 commit comments

Comments
 (0)