lomayor 3e6d3e7b12 WTP_to_GA
Removed preview note on WTP topics
2019-10-08 15:09:50 -07:00

4.0 KiB

title, description, keywords, search.product, search.appverid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, ms.author, author, ms.localizationpriority, manager, audience, ms.collection, ms.topic, ms.date
title description keywords search.product search.appverid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype ms.author author ms.localizationpriority manager audience ms.collection ms.topic ms.date
Respond to web threats in Microsoft Defender ATP Respond to alerts related to malicious and unwanted websites. Understand how web threat protection informs end users through their web browsers and Windows notifications web protection, web threat protection, web browsing, alerts, response, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser, notifications, end users, Windows notifications, blocking page, eADQiWindows 10XVcnh met150 w10 deploy library security lomayor lomayor medium dansimp ITPro M365-security-compliance article 08/30/2019

Respond to web threats

Want to experience Microsoft Defender ATP? Sign up for a free trial.

Web protection in Microsoft Defender ATP lets you efficiently investigate and respond to alerts related to malicious websites and websites in your custom indicator list.

View web threat alerts

Microsoft Defender ATP generates the following alerts for malicious or suspicious web activity:

  • Suspicious connection blocked by network protection — this alert is generated when an attempt to access a malicious website or a website in your custom indicator list is stopped by network protection in block mode
  • Suspicious connection detected by network protection — this alert is generated when an attempt to access a malicious website or a website in your custom indicator list is detected by network protection in audit only mode

Each alert provides the following information:

  • Machine that attempted to access the blocked website
  • Application or program used to send the web request
  • Malicious URL or URL in the custom indicator list
  • Recommended actions for responders

Image of an alert related to web threat protection

Note

To reduce the volume of alerts, Microsoft Defender ATP consolidates web threat detections for the same domain on the same machine each day to a single alert. Only one alert is generated and counted into the web protection report.

Inspect website details

You can dive deeper by selecting the URL or domain of the website in the alert. This opens a page about that particular URL or domain with various information, including:

  • Machines that attempted to access website
  • Incidents and alerts related to the website
  • How frequent the website was seen in events in your organization

Image of the domain or URL entity details page

Learn more about URL or domain entity pages

Inspect the machine

You can also check the machine that attempted to access a blocked URL. Selecting the name of the machine on the alert page opens a page with comprehensive information about the machine.

Learn more about machine entity pages

Web browser and Windows notifications for end users

With web protection in Microsoft Defender ATP, your end users will be prevented from visiting malicious or unwanted websites using Microsoft Edge or other browsers. Because blocking is performed by network protection, they will see a generic error from the web browser. They will also see a notification from Windows.

Image of Microsoft Edge showing a 403 error and the Windows notification Web threat blocked on Microsoft Edge

Image of Chrome web browser showing a secure connection warning and the Windows notification Web threat blocked on Chrome