From 847d916b597c5eb53a12303a5cf0f547b7ea3cbf Mon Sep 17 00:00:00 2001
From: amirsc3 <42802974+amirsc3@users.noreply.github.com>
Date: Wed, 25 Mar 2020 15:05:48 +0200
Subject: [PATCH 1/2] Update respond-file-alerts.md
Added improvement to note
---
.../microsoft-defender-atp/respond-file-alerts.md | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
index 8998da024b..2c33bef617 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
@@ -126,7 +126,8 @@ You can roll back and remove a file from quarantine if you’ve determined that
```
> [!NOTE]
-> Microsoft Defender ATP will restore all files that were quarantined on this machine in the last 30 days.
+> In some scenarios the ThreatName may appear as: EUS:Win32/CustomEnterpriseBlock!cl.
+> Microsoft Defender ATP will restore all custom blocked files that were quarantined on this machine in the last 30 days.
## Add indicator to block or allow a file
From c1a9ba5dbca10ad0b4cc947643b2782f636ca6fe Mon Sep 17 00:00:00 2001
From: amirsc3 <42802974+amirsc3@users.noreply.github.com>
Date: Wed, 25 Mar 2020 15:06:56 +0200
Subject: [PATCH 2/2] Update respond-file-alerts.md
---
.../microsoft-defender-atp/respond-file-alerts.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
index 2c33bef617..7c05201256 100644
--- a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
+++ b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md
@@ -126,7 +126,7 @@ You can roll back and remove a file from quarantine if you’ve determined that
```
> [!NOTE]
-> In some scenarios the ThreatName may appear as: EUS:Win32/CustomEnterpriseBlock!cl.
+> In some scenarios the ThreatName may appear as: EUS:Win32/CustomEnterpriseBlock!cl.
> Microsoft Defender ATP will restore all custom blocked files that were quarantined on this machine in the last 30 days.
## Add indicator to block or allow a file