You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/manage-automation-file-uploads.md
+8-3Lines changed: 8 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier2
13
13
ms.topic: conceptual
14
14
search.appverid: met150
15
-
ms.date: 05/08/2023
15
+
ms.date: 06/25/2024
16
16
---
17
17
18
18
# Manage automation file uploads
@@ -37,18 +37,23 @@ For example, if you add *exe* and *bat* as file or attachment extension names, t
37
37
> [!NOTE]
38
38
> Microsoft securely stores the files submitted for a six-month period. Files are promptly deleted after six months.
39
39
40
-
## Add file extension names and attachment extension names.
40
+
## Add file extension names and attachment extension names
41
41
42
-
1. Log in to [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
42
+
> [!IMPORTANT]
43
+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
44
+
45
+
1. Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
43
46
44
47
2. In the navigation pane, select **Settings**\>**Endpoints**\>**Rules**\>**Automation uploads**.
45
48
46
49
2. Toggle the content analysis setting between **On** and **Off**.
47
50
48
51
3. Configure the following extension names and separate extension names with a comma:
52
+
49
53
-**File extension names** - Suspicious files except email attachments will be submitted for additional inspection
Copy file name to clipboardExpand all lines: defender-endpoint/manage-automation-folder-exclusions.md
+14-6Lines changed: 14 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.collection:
14
14
ms.topic: conceptual
15
15
ms.subservice: edr
16
16
search.appverid: met150
17
-
ms.date: 12/18/2020
17
+
ms.date: 06/25/2024
18
18
---
19
19
20
20
# Manage automation folder exclusions
@@ -41,13 +41,17 @@ You can control the following attributes about the folder that you'd like to be
41
41
42
42
-**File names**: You can specify the file names that you want to be excluded in a specific directory. The names are a way to prevent an attacker from using an excluded folder to hide an exploit. The names explicitly define which files to ignore.
43
43
44
+
> [!IMPORTANT]
45
+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
46
+
47
+
44
48
## Add an automation folder exclusion
45
49
46
-
1.Log in to [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
50
+
1.Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
47
51
48
52
2. In the navigation pane, select **Settings**\>**Endpoints**\>**Rules**\>**Automation folder exclusions**.
49
53
50
-
2.Click**New folder exclusion**.
54
+
2.Select**New folder exclusion**.
51
55
52
56
3. Enter the folder details:
53
57
@@ -56,25 +60,29 @@ You can control the following attributes about the folder that you'd like to be
56
60
- File names
57
61
- Description
58
62
59
-
4.Click**Save**.
63
+
4.Select**Save**.
60
64
61
65
> [!NOTE]
62
66
> Live Response commands to collect or examine excluded files will fail with error: "File is excluded". In addition, automated investigations will ignore the excluded items.
63
67
64
68
## Edit an automation folder exclusion
65
69
66
70
1. In the navigation pane, select **Settings**\>**Endpoints**\>**Rules**\>**Automation folder exclusions**.
67
-
2. Click **Edit** on the folder exclusion.
71
+
72
+
2. Select **Edit** on the folder exclusion.
73
+
68
74
3. Update the details of the rule and click **Save**.
69
75
70
76
## Remove an automation folder exclusion
71
77
72
78
1. In the navigation pane, select **Settings**\>**Endpoints**\>**Rules**\>**Automation folder exclusions**.
Copy file name to clipboardExpand all lines: defender-endpoint/manage-suppression-rules.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,7 +34,7 @@ There might be scenarios where you need to suppress alerts from appearing in the
34
34
You can view a list of all the suppression rules and manage them in one place. You can also turn an alert suppression rule on or off.
35
35
36
36
37
-
1.Log in to [Microsoft Defender XDR](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
37
+
1.Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security administrator or Global administrator role assigned.
38
38
39
39
2. In the navigation pane, select **Settings**\>**Endpoints**\>**Rules**\>**Alert suppression**. The list of suppression rules that users in your organization have created is displayed.
0 commit comments