---
title: Manage Defender for Endpoint IOCs
description: Use this operation to add or remove Indicators of Compromise (IOCs) for Defender for Endpoint.
---

[Skip to content](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [TechOps](https://knowledge.sittadel.com/techops?hsLang=en)
3. [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)

# Manage Defender for Endpoint IOCs

## Use this operation to add or remove Indicators of Compromise (IOCs) for Defender for Endpoint.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-13-05-5511-PM.png?width=125&height=148&name=image-png-Jan-19-2024-04-13-05-5511-PM.png)**

### **Handbook Reference**

Package: **Device Security**

Domain: **Endpoint Indicator Management**

Modifies: **Allowed File Hashes, Allowed URLs/Domains, Allowed IP Addresses, Allowed Certificates, Blocked File Hashes, Blocked URLs/Domains, Blocked IP Addresses, Blocked Certificates**

### **![2024-12-17\_9-49-52](https://knowledge.sittadel.com/hs-fs/hubfs/Canva%20images/2024-12-17_9-49-52.png?width=125&height=103&name=2024-12-17_9-49-52.png)**

### **When to Perform this Operation**

As Needed: **Proactive or in Response to User/Security**

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Technical Description and Importance

Managing IOCs in Defender for Endpoint ensures that security teams can proactively allow or block specific threats based on intelligence. By adding allowed IOCs, organizations can ensure that trusted entities are not falsely flagged as threats, while blocking IOCs prevents known malicious entities from executing or communicating within the environment. Regularly updating IOCs based on threat intelligence supports proactive threat management and minimizes false positives. This operation is essential for aligning security enforcement with evolving organizational needs and emerging threats.

### Management Options

- [Allow a Certificate](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Allow-a-Certificate)
- [Allow a File Hash](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Allow-a-File-Hash)
- [Allow an IP](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Allow-an-IP)
- [Allow a URL/Domain](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Allow-a-URL-Domain)
- [Block a Certificate](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Block-a-Certificate)
- [Block a File](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Block-a-File-Hash)
- [Block an IP](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Block-an-IP)
- [Block a URL/Domain](https://knowledge.sittadel.com/manage-defender-for-endpoint-iocs#Block-a-URL-or-Domain)

#### ![2024-12-17\_10-15-21](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21.png?width=670&height=81&name=2024-12-17_10-15-21.png)

#### Allow a Certificate:

> **Purpose**  
> *Adds a certificate to the allow list to prevent false positives.*  
> **Use Case**  
> *A legitimate software vendor's certificate is mistakenly flagged as malicious.*

#### Allow a File:

> **Purpose**  
> *Adds a file hash to the allow list, ensuring it is not blocked.*  
> **Use Case**  
> *A business-critical application file is misclassified as a threat.*

#### Allow an IP:

> **Purpose**  
> *Adds an IP address to the allow list to permit network communication.*  
> **Use Case**  
> *A company's remote office IP is mistakenly blocked.*

#### Allow a URL/Domain:

> **Purpose**  
> *Adds a URL or domain to the allow list to enable access.*  
> **Use Case**  
> *A partner organization's website is erroneously blocked.*

#### Block a Certificate:

> **Purpose**  
> *Blocks a certificate to prevent execution of signed malware.*  
> **Use Case**  
> *A compromised certificate is being used for code signing attacks.*

#### Block a File:

> **Purpose**  
> *Blocks a file hash to prevent execution of malicious files.*  
> **Use Case**  
> *A known ransomware file hash must be proactively blocked.*

#### Block an IP:

> **Purpose**  
> *Blocks an IP address to prevent network communication.*  
> **Use Case**  
> *A known command-and-control server must be blocked.*

#### Block a URL/Domain:

> **Purpose**  
> *Blocks a URL or domain to prevent malicious web activity.*  
> **Use Case**  
> *A phishing website impersonating a trusted service needs to be blocked.*

*![2024-12-17\_10-15-21-1](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21-1.png?width=670&height=81&name=2024-12-17_10-15-21-1.png)*

| ###### **Operation** | ###### **Action** | ###### **Target** |
| --- | --- | --- |
| Allow a Certificate | **Addition** | Allowed Certificates |
| Allow a File Hash | **Addition** | Allowed File Hashes |
| Allow an IP | **Addition** | Allowed IP Addresses |
| Allow a URL/Domain | **Addition** | Allowed URLs/Domains |
| Block a Certificate | **Removal** | Blocked Certificates |
| Block a File Hash | **Removal** | Blocked File Hashes |
| Block an IP | **Removal** | Blocked IP Addresses |
| Block a URL/Domain | **Removal** | Blocked URLs/Domains |

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Allow a Certificate

This operation adds a certificate to the allowed list, preventing it from being flagged as a threat.

**      1. Defender for Endpoint Certificate IOC Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-certificate-ioc-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Allow a File Hash

This operation adds a file hash to the allow list, ensuring it is not blocked.

**      1. Defender for Endpoint File Hash IOC Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-file-hash-ioc-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Allow an IP

This operation adds an IP address to the allow list to enable network access.

**      1. Defender for Endpoint IP IOC Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-ip-ioc-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Allow a URL/Domain

This operation adds a URL or domain to the allow list, allowing traffic.

**      1. Defender for Endpoint URL/Domain IOC Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-url-domain-ioc-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Block a Certificate

This operation adds a certificate to the block list to prevent execution.

**      1. Defender for Endpoint Certificate IOC Block**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-certificate-ioc-block#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Block a File

This operation blocks a specific file hash from execution.

**      1. Defender for Endpoint File Hash IOC Block**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-file-hash-ioc-block#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Block an IP

This operation blocks an IP address from communicating within the network.

**      1. Defender for Endpoint IP IOC Block**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-ip-ioc-block#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Block a URL/Domain

This operation blocks a URL or domain from being accessed.

**      1. Defender for Endpoint URL/Domain IOC Block**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-endpoint-url-domain-ioc-block#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>