Skip to content

Commit

Permalink
Merge pull request #177 from vboyev-MSFT/patch-6
Browse files Browse the repository at this point in the history
Update defender-endpoint-false-positives-negatives.md -- Emm is reviewing
  • Loading branch information
emmwalshh authored Jan 23, 2025
2 parents 4dba218 + efe4604 commit 456b140
Showing 1 changed file with 2 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -212,9 +212,11 @@ To define exclusions across Microsoft Defender for Endpoint, perform the followi

- [Create "allow" indicators for Microsoft Defender for Endpoint](#indicators-for-defender-for-endpoint)
- [Define exclusions for Microsoft Defender Antivirus](#exclusions-for-microsoft-defender-antivirus)
- For Attack Surface Reduction Rule exclusions [Configure attack surface reduction per-rule exclusions](/defender-endpoint/attack-surface-reduction-rules-deployment-test#configure-attack-surface-reduction-per-rule-exclusions) or you can leverage [ASR rule only exclusions](/defender-endpoint/enable-attack-surface-reduction#exclude-files-and-folders-from-attack-surface-reduction-rules)

> [!NOTE]
> Microsoft Defender Antivirus exclusions apply only to antivirus protection, not across other Microsoft Defender for Endpoint capabilities. To exclude files broadly, use [custom indicators](indicators-overview.md) for Microsoft Defender for Endpoint and exclusions for Microsoft Defender Antivirus.
> ASR Rules can leverage ASR Rule Exclusions - where the exclusions apply to all ASR Rules; ASR per Rule Exclusions; Defender AV exclusions; as well as allow indicators defined in Custom Indicators.

The procedures in this section describe how to define indicators and exclusions.

Expand Down

0 comments on commit 456b140

Please sign in to comment.