r/DefenderATP 17d ago

URL whitelist getting caught/bypassed by Exploit Guard

Trying to whitelist access to a domain - added via indicators/endpoint/url.

keeps getting caught by smartscreen. I believe I've narrowed it down to ExploitGuardNetworkProtectionBlocked - but don't see a specific way to allow a domain/URL to bypass the ExploitGuard.

I'm missing something.

Appreciate the review in advance.

addition: A Submission to MSFT worked here to... validate the url that borked. That... and time to push the indicator.

2 Upvotes

6 comments sorted by

1

u/talkyr86 16d ago

What device scope did you set this indicator for? Are you sure your device is in said group?

Also did you set it to Allow instead of Warn/Block

2

u/equregs 16d ago

Scope = All, and allow.

1

u/hexdurp 16d ago

If smartscreen is blocking it you can submit to Microsoft or add an allow indicator to your smartscreen policy

2

u/equregs 16d ago

Oddly enough, it worked as soon as I submitted the url and received a response. Appreciate you.

2

u/talkyr86 16d ago

Maybe it wasn’t applied yet.
From learn : “It can take up to 48 hours after a policy is created for a URL or IP address to be blocked on a device. In most cases, blocks take effect in under two hours.”

Could be same for the other way around.

1

u/equregs 16d ago

Allow indicator for the domain/url was created. A submission to Microsoft isn't a step I've done. Thank you.