Update IP address range - Data Enrichment API


Microsoft Defender for Cloud Apps is now part of Microsoft 365 Defender, which correlates signals from across the Microsoft Defender suite and provides incident-level detection, investigation, and powerful response capabilities. For more information, see Microsoft Defender for Cloud Apps in Microsoft 365 Defender.

Run the POST request to update an existing IP address range.


This endpoint is not built for partial updates. All required parameters must be passed and any optional parameters will get an empty value if not passed.

HTTP request

POST /api/v1/subnet/<ip_range_id>/update_rule/

Request BODY parameters

Parameter Type Description
name string The unique name of the range
category int The id of the range category. Providing a category helps you easily recognize activities from interesting IP addresses. Possible values include:

1: Corporate
2: Administrative
3: Risky
4: VPN
5: Cloud provider
6: Other
subnets list An array of masks as strings (IPv4 / IPv6)
organization (Optional) string The registered ISP
tags (Optional) list An array of new or existing objects including the tag name, id, description, name template, and tenant id



Here is an example of the request.

curl -XPOST -H "Authorization:Token <your_token_key>" -H "Content-Type: application/json" "https://<tenant_id>.<tenant_region>.contoso.com/api/v1/subnet/<ip_range_id>/update_rule/" -d '{
  "name":"range name",
    "existing tag"

If you run into any problems, we're here to help. To get assistance or support for your product issue, please open a support ticket.