Create indicators based on certificates

Applies to:

Want to experience Defender for Endpoint? Sign up for a free trial.

You can create indicators for certificates. Some common use cases include:

  • Scenarios when you need to deploy blocking technologies, such as attack surface reduction rules but need to allow behaviors from signed applications by adding the certificate in the allow list.
  • Blocking the use of a specific signed application across your organization. By creating an indicator to block the certificate of the application, Windows Defender AV will prevent file executions (block and remediate) and the Automated Investigation and Remediation behave the same.

Before you begin

It's important to understand the following requirements prior to creating indicators for certificates:

  • This feature is available if your organization uses Microsoft Defender Antivirus and Cloud-based protection is enabled. For more information, see Manage cloud-based protection.

  • The Antimalware client version must be 4.18.1901.x or later.

  • Supported on machines on Windows 10, version 1703 or later, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, and Windows Server 2022.

    Note

    Windows Server 2016 and Windows Server 2012 R2 will need to be onboarded using the instructions in Onboard Windows servers for this feature to work.

  • The virus and threat protection definitions must be up to date.

  • This feature currently supports entering .CER or .PEM file extensions.

Important

  • A valid leaf certificate is a signing certificate that has a valid certification path and must be chained to the Root Certificate Authority (CA) trusted by Microsoft. Alternatively, a custom (self-signed) certificate can be used as long as it's trusted by the client (Root CA certificate is installed under the Local Machine 'Trusted Root Certification Authorities').
  • The children or parent of the allow/block certificate IOCs are not included in the allow/block IoC functionality, only leaf certificates are supported.
  • Microsoft signed certificates cannot be blocked.

Create an indicator for certificates from the settings page:

Important

It can take up to 3 hours to create and remove a certificate IoC.

  1. In the navigation pane, select Settings > Endpoints > Indicators (under Rules).

  2. Select Add indicator.

  3. Specify the following details:

    • Indicator - Specify the entity details and define the expiration of the indicator.
    • Action - Specify the action to be taken and provide a description.
    • Scope - Define the scope of the machine group.
  4. Review the details in the Summary tab, then click Save.

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.