Skip to content

Commit f03f5a3

Browse files
authored
Update indicator-ip-domain.md
1 parent ad2ab92 commit f03f5a3

File tree

1 file changed

+8
-5
lines changed

1 file changed

+8
-5
lines changed

defender-endpoint/indicator-ip-domain.md

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -65,15 +65,15 @@ It's important to understand the following prerequisites prior to creating indic
6565

6666
### Microsoft Defender Antivirus version requirements
6767

68-
This feature is available if your organization uses [Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-windows). Microsoft Defender Antivirus must be in active mode for non-Microsoft browsers. With Microsoft browsers, like Edge, this feature works whether Microsoft Defender Antivirus is in active or passive mode).
68+
- Your organization uses [Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-windows). Microsoft Defender Antivirus must be in active mode for non-Microsoft browsers. With Microsoft browsers, like Edge, Microsoft Defender Antivirus can be in active or passive mode.
6969

70-
[Behavior Monitoring](/defender-endpoint/behavior-monitor) is enabled
70+
- [Behavior Monitoring](/defender-endpoint/behavior-monitor) is enabled.
7171

72-
[Cloud-based protection](/windows/security/threat-protection/microsoft-defender-antivirus/deploy-manage-report-microsoft-defender-antivirus) is turned on.
72+
- [Cloud-based protection](/windows/security/threat-protection/microsoft-defender-antivirus/deploy-manage-report-microsoft-defender-antivirus) is turned on.
7373

74-
[Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is functional
74+
- [Cloud Protection network connectivity](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus) is turned on.
7575

76-
The antimalware client version must be `4.18.1906.x` or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates).
76+
- The antimalware client version must be `4.18.1906.x` or later. See [Monthly platform and engine versions](/defender-endpoint/microsoft-defender-antivirus-updates).
7777

7878
### Network Protection requirements
7979

@@ -142,7 +142,9 @@ Policy conflict handling for domains/URLs/IP addresses differ from policy confli
142142
In the case where multiple different action types are set on the same indicator (for example, **block**, **warn**, and **allow**, action types set for Microsoft.com), the order those action types would take effect is:
143143

144144
1. Allow
145+
145146
2. Warn
147+
146148
3. Block
147149

148150
"Allow" overrides "warn," which overrides "block", as follows: `Allow` > `Warn` > `Block`. Therefore, in the previous example, `Microsoft.com` would be allowed.
@@ -175,6 +177,7 @@ The result is that categories 1-4 are all blocked. This is illustrated in the fo
175177
3. Select **Add item**.
176178

177179
4. Specify the following details:
180+
178181
- Indicator - Specify the entity details and define the expiration of the indicator.
179182
- Action - Specify the action to be taken and provide a description.
180183
- Scope - Define the scope of the machine group.

0 commit comments

Comments
 (0)