diff --git a/windows/security/threat-protection/microsoft-defender-atp/indicator-ip-domain.md b/windows/security/threat-protection/microsoft-defender-atp/indicator-ip-domain.md index f859c87358..bda2d79c6e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/indicator-ip-domain.md +++ b/windows/security/threat-protection/microsoft-defender-atp/indicator-ip-domain.md @@ -57,7 +57,7 @@ It's important to understand the following prerequisites prior to creating indic > - Encrypted URLS (FQDN only) can be blocked outside of first party browsers (Internet Explorer, Edge) > - Full URL path blocks can be applied on the domain level and all unencrypted URLs ->[!NOTE] +> [!NOTE] >There may be up to 2 hours of latency (usually less) between the time the action is taken, and the URL and IP being blocked. ### Create an indicator for IPs, URLs, or domains from the settings page