Microsoft Defender Indicator Rules

JohnSmith-5837 46 Reputation points
2023-07-28T06:10:02.98+00:00

Hello,

I created two indicator rules in the security center (security.microsoft.com) based on the file hash. I set the indicator action to allow but it still triggers events and e-mails. Should i create a addiontal alert supression regarding this file hashes?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,373 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
417 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,053 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 48,591 Reputation points Microsoft Vendor
    2023-07-31T01:24:00.7433333+00:00

    @JohnSmith, Thanks for posting in Q&A. From your description, it seems the issue is with Microsoft Defender. To find the right support, you can contact the Defender support in the following link to get help:

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.