Forum Discussion

VolkerRacho's avatar
VolkerRacho
Copper Contributor
Nov 24, 2023

Disable Defender for Cloud Apps alerts

Hi all, 

 

we just enabled Defender for Cloud Apps in our environment (about 500 clients). 

We started with setting about 300 apps to "Unsanctioned".

 

Now we get flooded with alerts. Mainly "Connection to a custom network indicator on one endpoint" and "Multi-stage incident on multiple endpoints" when an URL is blocked on more clients.

 

 

Is there a possibility to disable the alerts for this kind of blocks?

I tried creating a supression rules, but didnt manage to get it working. Dont know if it is not possible or if I made a mistake.

As the Defender for Cloud Apps just creates a Indicator for every app i want to block I could click every single Indicator and disable the alert there. But thats a few hundred Indicators and we plan to extend the usage.

Can I centrally disable alerts for custom indicators?

 

Thanks & Cheers

2 Replies

Resources