Share via

Microsoft Defender Indicator Rules

David Rechtenbach 46 Reputation points
2023-07-28T06:10:02.98+00:00

Hello,

I created two indicator rules in the security center (security.microsoft.com) based on the file hash. I set the indicator action to allow but it still triggers events and e-mails. Should i create a addiontal alert supression regarding this file hashes?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Intune | Security
Microsoft Security | Intune | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 54,306 Reputation points Microsoft External Staff
    2023-07-31T01:24:00.7433333+00:00

    @JohnSmith, Thanks for posting in Q&A. From your description, it seems the issue is with Microsoft Defender. To find the right support, you can contact the Defender support in the following link to get help:

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.