Skip to content

Commit 6f9ea09

Browse files
authored
Merge pull request #2145 from MicrosoftDocs/manoj-156
2 parents 157357e + f47858f commit 6f9ea09

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

defender-endpoint/indicators-overview.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: conceptual
1616
ms.subservice: edr
1717
search.appverid: met150
18-
ms.date: 11/10/2024
18+
ms.date: 12/10/2024
1919
---
2020

2121
# Overview of indicators in Microsoft Defender for Endpoint
@@ -155,6 +155,8 @@ The IoC API schema and the threat IDs in advance hunting are updated to align wi
155155
> File and certificate indicators do not block [exclusions defined for Microsoft Defender Antivirus](/windows/security/threat-protection/microsoft-defender-antivirus/configure-exclusions-microsoft-defender-antivirus). Indicators are not supported in Microsoft Defender Antivirus when it is in passive mode.
156156
>
157157
> The format for importing new indicators (IoCs) has changed according to the new updated actions and alerts settings. We recommend downloading the new CSV format that can be found at the bottom of the import panel.
158+
>
159+
> If indicators are synced to the Microsoft Defender portal from Microsoft Defender for Cloud Apps for sanctioned or unsanctioned applications, the `Generate Alert` option is enabled by default in the Microsoft Defender portal. If you try to clear the `Generate Alert` option for Defender for Endpoint, it is re-enabled after some time because the Defender for Cloud Apps policy overrides it.
158160
159161
## Known issues and limitations
160162

@@ -176,4 +178,4 @@ Microsoft Store apps cannot be blocked by Defender because they're signed by Mic
176178
- [Use partner integrated solutions](partner-applications.md)
177179

178180

179-
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
181+
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)