From 4f60ac58c46877e206c2b47b39930c3e95d07ee5 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 3 Apr 2019 20:42:04 +0000 Subject: [PATCH 1/3] Updated manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md --- ...locked-list-windows-defender-advanced-threat-protection.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md index c11ff2b24d..cdcaa43100 100644 --- a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md @@ -57,7 +57,9 @@ On the top navigation you can: >[!NOTE] ->Blocking IPs, domains, or URLs is currently available on limited preview only. This requires sending your custom list to [network protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection) to be enforeced. While the option is not yet generally available, it will only be used when identified during an investigation. +>Blocking IPs, domains, or URLs is currently available on limited preview only. +>This requires sending your custom list to [network protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection) to be enforeced. +>When Automated investigations finds this indicator during an investigation, it will use the allowed/block list as the basis of its decision to automatically remdiate (blocked list) or skip (allowed list) the entity. ## Manage indicators From 8a6dabc34961d9be0dc22fcd6abfe735589fa6cf Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 3 Apr 2019 20:42:29 +0000 Subject: [PATCH 2/3] Updated manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md --- ...-blocked-list-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md index cdcaa43100..d596e4914b 100644 --- a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md @@ -59,7 +59,7 @@ On the top navigation you can: >[!NOTE] >Blocking IPs, domains, or URLs is currently available on limited preview only. >This requires sending your custom list to [network protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection) to be enforeced. ->When Automated investigations finds this indicator during an investigation, it will use the allowed/block list as the basis of its decision to automatically remdiate (blocked list) or skip (allowed list) the entity. +>When Automated investigations finds this indicator during an investigation, it will use the allowed/block list as the basis of its decision to automatically remediate (blocked list) or skip (allowed list) the entity. ## Manage indicators From 8f8915e1ad0eb426114e140de3d2571727b2f8bc Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 3 Apr 2019 20:49:01 +0000 Subject: [PATCH 3/3] Updated manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md --- ...locked-list-windows-defender-advanced-threat-protection.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md index d596e4914b..150cd87e78 100644 --- a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md @@ -58,8 +58,8 @@ On the top navigation you can: >[!NOTE] >Blocking IPs, domains, or URLs is currently available on limited preview only. ->This requires sending your custom list to [network protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection) to be enforeced. ->When Automated investigations finds this indicator during an investigation, it will use the allowed/block list as the basis of its decision to automatically remediate (blocked list) or skip (allowed list) the entity. +>This requires sending your custom list to [network protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection) to be enforced which is an option that will be generally available soon. +>As it is not yet generally available, when Automated investigations finds this indicator during an investigation it will use the allowed/block list as the basis of its decision to automatically remediate (blocked list) or skip (allowed list) the entity. ## Manage indicators