Forum Discussion
Issues blocking DeepSeek
What you are seeing usually means the block isn’t being fully enforced on the endpoint even though the domains or URIs exist as Indicators.
For Chrome and others, Defender for Endpoint enforces URL or domain blocks via Network Protection (Edge uses SmartScreen), so if Network Protection is not enabled in Block mode or Defender AV prerequisites aren’t fully met (i.e active mode, cloud-delivered protection, behavior monitoring), you will still see outbound HTTPS attempts but no block events.
For non‑Edge browsers, Defender derives the FQDN from the TLS handshake, so if traffic uses QUIC or HTTP3 or Encrypted ClientHello (ECH), domain blocking can be bypassed or effective and you’ll again see “successful” connections with no recorded blocks.
To make this consistent, I would say ensure your indicators are Domain or FQDN based e.g. deepseek.com, not the full HTTPS URL paths which are limited outside Edge and verify Custom network indicators and Network Protections block mode are enabled and deployed to the relevant device groups.
Allow at least 2-3 hours for the enforcement to be in effect.
If you find the answer useful, please do not forget to like and mark it as a solution