How to Manage Indicators in Microsoft Defender for Business vs Endpoint
Question details
The user needs to understand the differences between Microsoft Defender for Business and Microsoft Defender for Endpoint regarding indicator management and how to configure allow or block actions.
- Product
- Microsoft Defender for Business
- Device & OS
- not provided
- Scenario
- Configuring security indicators and comparing scoping features between Defender for Business and Defender for Endpoint.
- Observed behavior
- Defender for Business allows managing indicators of compromise like IP addresses and file hashes, while Defender for Endpoint provides more advanced scoping and device-group capabilities.
Ensure you have administrative access to the Microsoft 365 Defender portal and check whether your subscription is tailored for Business or Enterprise to verify available feature scopes.
Configure Allow or Block Indicators in Defender for Business
Set up security rules for IP addresses, URLs, domains, and file hashes within the Microsoft Defender for Business environment.
Microsoft Defender for Business indicators function similarly to those in Defender for Endpoint, allowing you to control network traffic and file execution by defining indicators of compromise (IoCs).
Log in to the Microsoft 365 Defender portal using your administrator credentials.
Go to 'Settings' in the left-hand navigation menu, then select 'Endpoints'.
Click on 'Rules' and then select 'Indicators' to view and manage your current indicators of compromise.
Add the specific IP addresses, URLs, domains, or file hashes you wish to control, and assign 'Allow' or 'Block' actions to them.
Evaluate Advanced Capabilities Using a Trial Tenant
If you are unsure whether Defender for Business meets your organization's complex scoping needs, test the features in a dedicated environment.
Looking for a secure and lightweight Office alternative?
While configuring complex Microsoft security settings like Defender for Business, you might also be looking for a streamlined, cost-effective office suite for your team. WPS Office offers exceptional compatibility with Microsoft formats in an easy-to-manage package.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the installer and follow the simple on-screen instructions to set up the software.
- 3. Open Your Files Seamlessly: Launch WPS Office and instantly open your existing Microsoft Office documents without format loss.

Frequently Asked Questions
What are indicators of compromise (IoCs) in Microsoft Defender?
Indicators of compromise are digital artifacts such as IP addresses, URLs, domains, and file hashes that Microsoft Defender uses to identify and block potentially malicious activity across your organization's devices.
Does Defender for Business support device groups for indicator rules?
Defender for Business provides standard indicator management capabilities. Advanced scoping and specific device-group targeting are primarily available in Microsoft Defender for Endpoint.
How do I block a specific IP address in Defender for Business?
You can block an IP address by logging into the Microsoft 365 Defender portal, navigating to Settings > Endpoints > Rules > Indicators, adding the specific IP, and setting its action to 'Block'.




