Fix Microsoft Defender for Endpoint CSV Import Failure for Indicators of Compromise
Question details
The user is unable to import Indicators of Compromise (IoC) into Microsoft Defender for Endpoint using a CSV file and is seeking an alternative method.

- Product
- Microsoft Defender for Endpoint
- Device & OS
- not provided
- Scenario
- Attempting to bulk import security indicators using the official Microsoft CSV sample template in the Defender portal.
- Observed behavior
- The CSV import process fails completely, rejecting the data even when the official sample template is used.
Before troubleshooting, ensure you have the appropriate 'Manage security settings in Security Center' administrative permissions and that your CSV file is closed in any background spreadsheet applications.
Verify CSV Schema and Formatting Rules
Use this solution to ensure your CSV file strictly adheres to the required Microsoft Defender data types and mandatory fields.
CSV import failures often occur due to hidden formatting issues, unsupported characters, or missing mandatory fields that aren't immediately obvious, even when using the official template.
Right-click your CSV file and select 'Open with' > 'Notepad' or a dedicated spreadsheet editor to check for trailing spaces or misplaced commas.
Check that your file includes exactly the required columns: indicatorValue, indicatorType, action, and expirationTime. Ensure the column headers perfectly match Microsoft's documentation without extra spaces.
Ensure that the 'expirationTime' column is formatted correctly (e.g., YYYY-MM-DDThh:mm:ssZ) and that no blank rows exist at the bottom of your data set.
In your spreadsheet editor, go to 'File' > 'Save As', and explicitly choose 'CSV (Comma delimited) (*.csv)' to avoid saving in a proprietary spreadsheet format by mistake.

Engage the Microsoft Defender Technical Community
Since this is an enterprise security issue outside standard community support, reaching out to specialized Microsoft Defender experts is the most effective next step.
Edit and Validate CSV Files Seamlessly with WPS Office
If you are struggling with formatting CSV files for security imports in Excel, WPS Office provides a free, lightweight, and highly compatible alternative. WPS Spreadsheet makes it incredibly easy to inspect raw data, remove hidden formatting, and save clean CSV files without data corruption.
- 1. Install WPS Office: Download and install the free version of WPS Office from the official website.
- 2. Open Your CSV File: Launch WPS Spreadsheet and drag-and-drop your Indicators of Compromise CSV file into the workspace.
- 3. Edit and Save: Clean up any formatting errors, remove empty rows, and go to Menu > Save As > CSV to generate a pristine import file.

Frequently Asked Questions
Why does my CSV fail to import even when using the official Microsoft sample template?
This commonly happens if you edit the template in a spreadsheet program that automatically changes the date format of the 'expirationTime' column, or if trailing spaces are inadvertently added to the 'indicatorValue' column during copy-pasting.
What are the required fields for an IoC CSV import in Defender?
At a minimum, your CSV must contain the 'indicatorValue' (the actual IP, URL, or hash), 'indicatorType' (FileSha256, IpAddress, Url, etc.), and 'action' (Alert, AlertAndBlock, or Allowed). Some indicator types also strictly require a title or severity.
Is there an alternative to CSV imports for adding Indicators of Compromise?
Yes. If bulk CSV import fails, you can manually add indicators one by one directly in the Microsoft 365 Defender portal under Settings > Endpoints > Indicators, or you can automate the process using the Microsoft Defender for Endpoint API.
How can I check if I have the right permissions to import indicators?
Log into the Microsoft 365 Defender portal, navigate to Settings > Endpoints > Roles, and verify that your user account is assigned to a role that includes the 'Manage security settings in Security Center' permission.




