An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
To block a sender or URL that has come through the Scareware Blocker, you can add the URL to the Tenant Allow/Block List in the Microsoft Defender portal. However, it seems you are encountering an issue where only the option to add sites to a "never block" list is available.
Here’s how you can create a block entry for URLs:
- Go to the Microsoft Defender portal at https://security.microsoft.com.
- Navigate to Email & collaboration > Policies & rules > Threat policies > Rules section > Tenant Allow/Block Lists.
- Select the URLs tab.
- Click on Add, and then select Block.
- In the Block URLs flyout, enter the URL you want to block. You can add multiple URLs, one per line, up to a maximum of 20.
- Configure any additional settings, such as how long you want the block entry to last.
This should allow you to block the scareware website effectively. If you continue to experience issues, ensure that your Microsoft Defender settings are correctly configured and that you have the necessary permissions to make these changes.