Forum Discussion
Exclude Device in Defender for endpoint
In the DfE GUI on security.microsoft.com it is possible to exclude a device manually adding a justification (eg Duplicate device) and additional Notes.
Now I'd like to use an API - probably the Windows Defender ATP API - for this task.
But it seems it is only possible to offboard the device, but not to exclude it.
Is it somehow possible to exclude the device via an API?
tia
7 Replies
pwahlmueller i think the only supported MDE APIs are as follow in the link
and from the machine action section , most of the actions are listed except the exclude device action
machineAction resource type | Microsoft Learn
I will ask in the CCP is there is a roadmap for this
This is what I found yet. Not fully satisfying.
https://practical365.com/handling-inactive-devices-in-microsoft-defender-for-endpoint/
- PerBCopper Contributor
elieelkarkafi Any update?
- No update yet on this API to exclude devices in MDE
- lukescottCopper Contributor
Hey elieelkarkafi ,
Do you have an update regarding this?
Also, is there a specific reason why the offboard machine action is OS-specific?
Kind regards,
Luke