Forum Discussion
Indicator Policy Change with Defender takes more than 2 hours
Hi,
We have recently ran into an issue that indicator was created through automation to block a benign URL (Shxt happens) and removal of the IoC did not sync with devices for 6 hours, maybe even more. We had a support case with Microsoft etc. but I am curious if there is any documented information anywhere by Microsoft to know how long those time intervals are for specific changes, why a block IoC takes 2 hours or less to be implemented on devices but whitelist or removal of IoC takes more?
Any ideas?
Thanks!
7 Replies
- ItsBhattiIron Contributor
If you're experiencing a delay of more than two hours when trying to change the indicator policy in Windows Defender, there are several possible reasons behind this issue. Here are some troubleshooting steps to help resolve it:
System Resources: Insufficient system resources, such as CPU or RAM, can lead to delays in policy changes. Ensure that your computer has adequate resources available for this operation by closing unnecessary applications and processes.
Check for Updates: Make sure that your Windows Defender software and your operating system are up-to-date. Outdated software can sometimes cause performance issues. Check for updates in Windows Update and Windows Security settings.
Security Software Conflicts: Other security software or third-party antivirus programs can conflict with Windows Defender and cause delays. Consider temporarily disabling or uninstalling any third-party security software to see if it resolves the issue.
Scan for Malware: Run a full system scan with Windows Defender to check for malware or potentially unwanted programs (PUPs). Malware infections can disrupt normal system operations, including policy changes.
Policy Complexity: Complex policy changes may take longer to apply. Ensure that the policy changes you're making are necessary and not overly complicated. Simplify the policies if possible.
Network Connection: If your computer is managed by a network administrator, the delay could be due to network-related issues. Ensure that your network connection is stable and that there are no network bottlenecks causing delays.
Group Policy Settings: If you're making changes to Defender policies through Group Policy, ensure that Group Policy updates are being applied correctly. You can force a Group Policy update by running the "gpupdate /force" command in Command Prompt with administrative privileges.
System Performance: Check your computer's overall performance. If it's slow in general, the policy change process may also be affected. Consider optimizing your system for better performance.
Event Logs: Review the Windows Event Viewer logs for any error messages or warnings related to the policy change. This can provide clues about what might be causing the delay.
Windows Defender Repair: If none of the above steps resolve the issue, you can try repairing Windows Defender. To do this, open "Settings," go to "Apps," select "Microsoft Defender Antivirus," click on "Advanced options," and then click "Repair."
Contact Support: If the problem persists after trying these steps, consider contacting Microsoft Support or your organization's IT support for further assistance. They may be able to provide more specific guidance based on your system's configurationhttps://validautodocs.com/
Keep in mind that changing security policies can have a significant impact on your computer's security settings, so it's important to ensure that these changes are made correctly and with a full understanding of their implications.
- EwilcoshBrass ContributorDid you hear back from Microsoft? Do you have a way to speed up whitelisting, or an expected timeline?
Didi00 There may be up to 2 hours of latency between the time a policy is created and the URL or IP being blocked on the device.
Create indicators for IPs and URLs/domains | Microsoft Learn
MDE has a scheduled lifecycle when you change or create any policy and some of the policies requires up to 6-12 hours to affect the targeted devices.
- Didi00Copper Contributor
Thanks a lot for your response.
6-12 hours has 6 hours in between which is a huge amount of time when you roll back a change...
l couldnt find anywhere in documentation this being mentioned. Thanks again!
Didi00 i suggest you open a ticket with the security team so they can check the timeline of your tenant lifecycle and you may request if they can decrease the timing of the policy changes effect