You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/indicator-ip-domain.md
+23-16Lines changed: 23 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,38 +46,45 @@ You can block malicious IPs/URLs through the settings page or by machine groups,
46
46
> [!NOTE]
47
47
> Classless Inter-Domain Routing (CIDR) notation for IP addresses is not supported.
48
48
49
-
## Before you begin
50
-
51
-
It's important to understand the following prerequisites prior to creating indicators for IPS, URLs, or domains:
52
-
53
-
### Network Protection requirements
54
-
55
-
URL/IP allow and block requires that the Microsoft Defender for Endpoint component _Network Protection_ is enabled in block mode. For more information on Network Protection and configuration instructions, see [Enable network protection](enable-network-protection.md).
56
-
57
49
### Supported operating systems
58
50
59
-
- Windows 10, version 1709 or later
60
51
- Windows 11
61
-
- Windows Server 2016
62
-
- Windows Server 2012 R2
63
-
- Windows Server 2019
52
+
53
+
- Windows 10, version 1709 or later
64
54
- Windows Server 2022
55
+
- Windows Server 2019
56
+
- Windows Server 2016 running [Defender for Endpoint modern unified solution](/defender-endpoint/configure-server-endpoints) (requires installation through MSI)
57
+
58
+
- Windows Server 2012 R2 running [Defender for Endpoint modern unified solution](/defender-endpoint/configure-server-endpoints) (requires installation through MSI)
59
+
65
60
- macOS
66
61
- Linux
67
62
- iOS
68
63
- Android
69
64
70
-
### Windows Server 2016 and Windows Server 2012 R2 requirements
65
+
##Before you begin
71
66
72
-
Windows Server 2016 and Windows Server 2012 R2 must be onboarded using the instructions in [Onboard Windows servers](configure-server-endpoints.md#windows-server-2016-and-windows-server-2012-r2).
67
+
It's important to understand the following prerequisites prior to creating indicators for IPS, URLs, or domains:
73
68
74
69
### Microsoft Defender Antivirus version requirements
75
70
76
-
The _Antimalware client version_ must be 4.18.1906.x or later.
71
+
This feature is available if your organization uses [Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-windows) (in active mode)
72
+
73
+
[Behavior Monitoring](/defender-endpoint/behavior-monitor) is enabled
74
+
75
+
[Cloud-based protection](/windows/security/threat-protection/microsoft-defender-antivirus/deploy-manage-report-microsoft-defender-antivirus) is turned on.
76
+
77
+
[Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is functional
78
+
79
+
The *Antimalware client version* must be 4.18.1906.x or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates)
80
+
81
+
### Network Protection requirements
82
+
83
+
URL/IP allow and block requires that the Microsoft Defender for Endpoint component _Network Protection_ is enabled in **block mode**. For more information on Network Protection and configuration instructions, see [Enable network protection](enable-network-protection.md).
77
84
78
85
### Custom network indicators requirements
79
86
80
-
Ensure that **Custom network indicators**is enabled in **Microsoft Defender XDR**\>**Settings**\>**Advanced features**. For more information, see [Advanced features](advanced-features.md).
87
+
To start blocking IP addresses and/or URL's, turn on "**Custom network indicators"**feature in **Microsoft Defender XDR**(in the Microsoft Defender portal), go to **Settings**> **Endpoints** > **General**> **Advanced features**. For more information, see [Advanced features](advanced-features.md).
81
88
82
89
For support of indicators on iOS, see [Microsoft Defender for Endpoint on iOS](ios-configure-features.md#configure-custom-indicators).
0 commit comments