logo
search
Security Policy Errors

Fix Microsoft Defender for Endpoint CSV Import Failure for Indicators of Compromise

Huda QurayshiHuda Qurayshi Sep 30, 2026 869 views

Question details

The user is unable to import Indicators of Compromise (IoC) into Microsoft Defender for Endpoint using a CSV file and is seeking an alternative method.

How to Resolve CSV Import Failures for Indicators of Compromise in Microsoft Defender
Product
Microsoft Defender for Endpoint
Device & OS
not provided
Scenario
Attempting to bulk import security indicators using the official Microsoft CSV sample template in the Defender portal.
Observed behavior
The CSV import process fails completely, rejecting the data even when the official sample template is used.
Before you start

Before troubleshooting, ensure you have the appropriate 'Manage security settings in Security Center' administrative permissions and that your CSV file is closed in any background spreadsheet applications.

Solution 1Recommended

Verify CSV Schema and Formatting Rules

Use this solution to ensure your CSV file strictly adheres to the required Microsoft Defender data types and mandatory fields.

CSV import failures often occur due to hidden formatting issues, unsupported characters, or missing mandatory fields that aren't immediately obvious, even when using the official template.

1
Open the CSV in a plain editor

Right-click your CSV file and select 'Open with' > 'Notepad' or a dedicated spreadsheet editor to check for trailing spaces or misplaced commas.

2
Verify mandatory columns

Check that your file includes exactly the required columns: indicatorValue, indicatorType, action, and expirationTime. Ensure the column headers perfectly match Microsoft's documentation without extra spaces.

3
Check data formatting

Ensure that the 'expirationTime' column is formatted correctly (e.g., YYYY-MM-DDThh:mm:ssZ) and that no blank rows exist at the bottom of your data set.

4
Save as Standard CSV

In your spreadsheet editor, go to 'File' > 'Save As', and explicitly choose 'CSV (Comma delimited) (*.csv)' to avoid saving in a proprietary spreadsheet format by mistake.

Verify CSV Schema and Formatting Rules
File Size Limits: Microsoft Defender for Endpoint limits CSV imports to a maximum of 500 indicators per file. If your list is larger, split it into multiple smaller CSV files.
Free Microsoft Office alternative

Edit and Validate CSV Files Seamlessly with WPS Office

If you are struggling with formatting CSV files for security imports in Excel, WPS Office provides a free, lightweight, and highly compatible alternative. WPS Spreadsheet makes it incredibly easy to inspect raw data, remove hidden formatting, and save clean CSV files without data corruption.

  1. 1. Install WPS Office: Download and install the free version of WPS Office from the official website.
  2. 2. Open Your CSV File: Launch WPS Spreadsheet and drag-and-drop your Indicators of Compromise CSV file into the workspace.
  3. 3. Edit and Save: Clean up any formatting errors, remove empty rows, and go to Menu > Save As > CSV to generate a pristine import file.
Perfect format compatibility with Microsoft Excel (.xlsx, .xls, .csv).Lightweight and lightning-fast, making it ideal for opening large data log files.Clean, familiar user interface ensuring a seamless migration from Microsoft Office.Advanced data validation tools to help you verify your IoC fields before importing.
QA img-9

Frequently Asked Questions

Why does my CSV fail to import even when using the official Microsoft sample template?

This commonly happens if you edit the template in a spreadsheet program that automatically changes the date format of the 'expirationTime' column, or if trailing spaces are inadvertently added to the 'indicatorValue' column during copy-pasting.

What are the required fields for an IoC CSV import in Defender?

At a minimum, your CSV must contain the 'indicatorValue' (the actual IP, URL, or hash), 'indicatorType' (FileSha256, IpAddress, Url, etc.), and 'action' (Alert, AlertAndBlock, or Allowed). Some indicator types also strictly require a title or severity.

Is there an alternative to CSV imports for adding Indicators of Compromise?

Yes. If bulk CSV import fails, you can manually add indicators one by one directly in the Microsoft 365 Defender portal under Settings > Endpoints > Indicators, or you can automate the process using the Microsoft Defender for Endpoint API.

How can I check if I have the right permissions to import indicators?

Log into the Microsoft 365 Defender portal, navigate to Settings > Endpoints > Roles, and verify that your user account is assigned to a role that includes the 'Manage security settings in Security Center' permission.