logo
search
Security Policy Errors

How to Manage Indicators in Microsoft Defender for Business vs Endpoint

Maira MehtabMaira Mehtab Sep 21, 2026 868 views

Question details

The user needs to understand the differences between Microsoft Defender for Business and Microsoft Defender for Endpoint regarding indicator management and how to configure allow or block actions.

Product
Microsoft Defender for Business
Device & OS
not provided
Scenario
Configuring security indicators and comparing scoping features between Defender for Business and Defender for Endpoint.
Observed behavior
Defender for Business allows managing indicators of compromise like IP addresses and file hashes, while Defender for Endpoint provides more advanced scoping and device-group capabilities.
Before you start

Ensure you have administrative access to the Microsoft 365 Defender portal and check whether your subscription is tailored for Business or Enterprise to verify available feature scopes.

Solution 1Recommended

Configure Allow or Block Indicators in Defender for Business

Set up security rules for IP addresses, URLs, domains, and file hashes within the Microsoft Defender for Business environment.

Microsoft Defender for Business indicators function similarly to those in Defender for Endpoint, allowing you to control network traffic and file execution by defining indicators of compromise (IoCs).

1
Access the Defender Portal

Log in to the Microsoft 365 Defender portal using your administrator credentials.

2
Navigate to Endpoints Settings

Go to 'Settings' in the left-hand navigation menu, then select 'Endpoints'.

3
Open Indicator Rules

Click on 'Rules' and then select 'Indicators' to view and manage your current indicators of compromise.

4
Add and Configure Actions

Add the specific IP addresses, URLs, domains, or file hashes you wish to control, and assign 'Allow' or 'Block' actions to them.

Scoping Limitations: Defender for Business offers standard indicator management. If you require advanced device-group targeting or broader scoping options, you may need Microsoft Defender for Endpoint.
Free Microsoft Office alternative

Looking for a secure and lightweight Office alternative?

While configuring complex Microsoft security settings like Defender for Business, you might also be looking for a streamlined, cost-effective office suite for your team. WPS Office offers exceptional compatibility with Microsoft formats in an easy-to-manage package.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the installer and follow the simple on-screen instructions to set up the software.
  3. 3. Open Your Files Seamlessly: Launch WPS Office and instantly open your existing Microsoft Office documents without format loss.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight design ensures fast installation and minimal system resource consumption.Cost-effective solution tailored for individuals and small to medium businesses.Enterprise-grade document security with built-in PDF editing tools.
microsoft office alternative - wps office

Frequently Asked Questions

What are indicators of compromise (IoCs) in Microsoft Defender?

Indicators of compromise are digital artifacts such as IP addresses, URLs, domains, and file hashes that Microsoft Defender uses to identify and block potentially malicious activity across your organization's devices.

Does Defender for Business support device groups for indicator rules?

Defender for Business provides standard indicator management capabilities. Advanced scoping and specific device-group targeting are primarily available in Microsoft Defender for Endpoint.

How do I block a specific IP address in Defender for Business?

You can block an IP address by logging into the Microsoft 365 Defender portal, navigating to Settings > Endpoints > Rules > Indicators, adding the specific IP, and setting its action to 'Block'.