Skip to content

Commit fc74cd5

Browse files
authored
Update indicator-manage.md
Added note under parameter table to detail that network indicators cannot have the action parameter set to BlockAndRemediate.
1 parent f4e7e5b commit fc74cd5

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

defender-endpoint/indicator-manage.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,9 @@ The following table shows the supported parameters.
7979
> Classless Inter-Domain Routing (CIDR) notation for IP addresses is not supported.
8080
For more information, see [Microsoft Defender for Endpoint alert categories are now aligned with MITRE ATT&CK!](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-atp-alert-categories-are-now-aligned-with/ba-p/732748).
8181

82+
> [!NOTE]
83+
> Network Indicators 'action' type does not support the use of *BlockAndRemediate*. The Network indicator will not import if it is set to *BlockAndRemediate*.
84+
8285
Watch this video to learn how Microsoft Defender for Endpoint provides multiple ways to add and manage Indicators of compromise (IoCs).
8386
> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RE4qLVw]
8487

0 commit comments

Comments
 (0)