indicators for URLs not blocking any longer

%3CLINGO-SUB%20id%3D%22lingo-sub-1123231%22%20slang%3D%22en-US%22%3Eindicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1123231%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3Eis%20there%20a%20known%20issue%20with%20Indicators%20for%20URLs%2Fdomains%3F%3C%2FP%3E%3CP%3Ewe%20recognised%20that%20blocking%20rules%20stop%20working%20for%20non-edge%20browsers%20and%20edge%20browser%20smart%20screen%20needs%20a%20refresh%20of%20the%20site%20in%20order%20to%20block%20the%20access.%3C%2FP%3E%3CP%3Enetwork%20protection%20on%20the%20client%20(1903)%20is%20enabled%20and%20verified.%3C%2FP%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3CP%3Ethank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1125918%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1125918%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239335%22%20target%3D%22_blank%22%3E%40Thomas%20H%C3%B6hner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20just%20demonstrated%20this%20today%20with%20a%20customer%20on%20my%20own%20and%20on%20one%20of%20their%20devices%2C%20worked%20fine%20with%20Chrome%20on%20Windows%2010%201909%20and%201903%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20see%20any%20information%20in%20the%20Windows%20Event%20log%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CTABLE%20border%3D%220%22%3E%3CTBODY%3E%3CTR%3E%3CTD%3E%3CSTRONG%3Enetwork%20protection%3C%2FSTRONG%3E%3C%2FTD%3E%3CTD%3EMicrosoft-Windows-Windows-Defender%2FOperational%3C%2FTD%3E%3CTD%3E5007%3C%2FTD%3E%3CTD%3EEvent%20when%20settings%20are%20changed%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E1125%3C%2FTD%3E%3CTD%3EEvent%20when%20a%20network%20connection%20is%20audited%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E1126%3C%2FTD%3E%3CTD%3EEvent%20when%20a%20network%20connection%20is%20blocked%3C%2FTD%3E%3C%2FTR%3E%3C%2FTBODY%3E%3C%2FTABLE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1126806%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1126806%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F24027%22%20target%3D%22_blank%22%3E%40Alex%20Verboon%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%20for%20your%20reply.%3C%2FP%3E%3CP%3Ein%20case%20your%20indicator%20works%20as%20expected%20and%20the%20block%20is%20applied%20successfully%20-%20how%20does%20your%20indicator%20entry%20for%20the%20related%20domain%2Furl%20looks%20like%3F%3C%2FP%3E%3CP%3EFigured%20out%20that%20indeed%20a%20domain%20name%20like%20google.com%20works%20pretty%20fine%2C%20but%20in%20case%20you're%20moving%20deeper%20into%20a%20URL%20path%2C%20it%20does%20not%20-%20for%20instance%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2F%3Fgl%3DDE%26amp%3Btab%3Dw11%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.youtube.com%2F%3Fgl%3DDE%26amp%3Btab%3Dw11%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1127990%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1127990%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239335%22%20target%3D%22_blank%22%3E%40Thomas%20H%C3%B6hner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20had%20conifgured%20%3CA%20href%3D%22http%3A%2F%2Fwww.bitcoin.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.bitcoin.com%3C%2FA%3E%2C%20here's%20the%20result.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F167097i1C637A06BEF2289D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3Ehaven't%20tried%20the%20case%20you%20described%20but%20will%20try%20out%20as%20well%20and%20let%20you%20know%20the%20results%20.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1130861%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1130861%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239335%22%20target%3D%22_blank%22%3E%40Thomas%20H%C3%B6hner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20are%20working%20to%20support%20this%20case%20as%20well.%3C%2FP%3E%0A%3CP%3EPlease%20read%20through%20the%20following%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fmanage-indicators%23create-indicators-for-ips-and-urlsdomains-preview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Edocumentation%20section.%3C%2FA%3E%3CBR%20%2F%3E%3CSPAN%20style%3D%22display%3A%20inline%20!important%3B%20float%3A%20none%3B%20background-color%3A%20%23e0f2ff%3B%20color%3A%20%23171717%3B%20font-family%3A%20Segoe%20UI%2CSegoeUI%2CSegoe%20WP%2CHelvetica%20Neue%2CHelvetica%2CTahoma%2CArial%2Csans-serif%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20400%3B%20letter-spacing%3A%20normal%3B%20list-style-image%3A%20none%3B%20list-style-position%3A%20outside%3B%20list-style-type%3A%20disc%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-decoration%3A%20none%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%3EFull%20URL%20path%20blocks%20can%20be%20applied%20on%20the%20domain%20level%20and%20all%20unencrypted%20URLs.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335337%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335337%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F149712%22%20target%3D%22_blank%22%3E%40Efrat%20Kliger%3C%2FA%3E%26nbsp%3B-%20Hi%20having%20the%20same%20issue%2C%20URL%20indicators%20look%20correct%20but%20blocking%20stopped%20working%20in%20IE%2FChrome%20and%20only%20intermittently%20blocks%20in%20Edge.%26nbsp%3B%20Have%20raised%20a%20support%20request%20w%2FMS.%20If%20anyone%20has%20insight%20on%20root%20cause%20would%20appreciate%20feedback%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335346%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335346%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F341595%22%20target%3D%22_blank%22%3E%40Scott650%3C%2FA%3E%3C%2FP%3E%3CP%3EHi%20Scott%2C%3C%2FP%3E%3CP%3EI%20assume%20you're%20talking%20about%20the%20https%20related%20deep%20links%2C%20which%20are%20not%20blocked%20by%20CI%20as%20%22expected%22%20-%20from%20my%20understanding%20this%20is%20currently%20by%20design%2C%20as%20mdatp%20does%20not%20act%20as%20%22man%20in%20the%20middle%22%20breaking%20up%20the%20encrypted%20channel%20between%20the%20browser%20and%20the%20related%20webserver.%20Thus%20the%20only%20way%20to%20block%20https%20related%20URLs%20is%20to%20configure%20the%20related%20CI%20for%20the%20domain%20in%20general%3A%3C%2FP%3E%3CP%3Eworking%20%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.google.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.google.com%3C%2FA%3E%3C%2FP%3E%3CP%3Enot%20working%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.google.com%2Fwhatever-deep-link%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.google.com%2Fwhatever-deep-link%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335357%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335357%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239335%22%20target%3D%22_blank%22%3E%40Thomas%20H%C3%B6hner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BSimply%20marked%20Zoom%20as%20unsanctioned%20in%20MCAS%2C%20worked%20for%20~3%20week%20and%20the%20just%20stopped.%3C%2FP%3E%3CP%3EAllowed%20the%20integration%20between%20MCAS%20and%20Defender%20ATP%20to%20automatically%20create%20the%20indicator.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335804%22%20slang%3D%22en-US%22%3ERe%3A%20indicators%20for%20URLs%20not%20blocking%20any%20longer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335804%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F341595%22%20target%3D%22_blank%22%3E%40Scott650%3C%2FA%3E%26nbsp%3BHi%20-%20determined%20that%20someone%20unlinked%20a%20GPO%20that%20enforced%20network%20protection.%26nbsp%3B%20The%20reason%20Edge%20worked%20was%20due%20to%20smartscreen.%20The%20Key%26nbsp%3B%3CSPAN%3EHKEY_LOCAL_MACHINE%5CSOFTWARE%5CPolicies%5CMicrosoft%5CWindows%20Defender%5CWindows%20Defender%20Exploit%20Guard%5CNetwork%20Protection%5C%3CSTRONG%3EEnableNetworkProtection%3D1%26nbsp%3B%20did%20not%20exist.%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3Ethat%20was%20our%20root%20cause%20-%20hope%20this%20helps%20others%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fenable-network-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fenable-network-protection%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi,

is there a known issue with Indicators for URLs/domains?

we recognised that blocking rules stop working for non-edge browsers and edge browser smart screen needs a refresh of the site in order to block the access.

network protection on the client (1903) is enabled and verified.

Any ideas?

thank you

8 Replies
Highlighted

@Thomas Höhner 

 

I just demonstrated this today with a customer on my own and on one of their devices, worked fine with Chrome on Windows 10 1909 and 1903

 

Do you see any information in the Windows Event log?

 

network protectionMicrosoft-Windows-Windows-Defender/Operational5007Event when settings are changed
1125Event when a network connection is audited
1126Event when a network connection is blocked

 

 

 

 

Highlighted

Hi @Alex Verboon 

 

thanks for your reply.

in case your indicator works as expected and the block is applied successfully - how does your indicator entry for the related domain/url looks like?

Figured out that indeed a domain name like google.com works pretty fine, but in case you're moving deeper into a URL path, it does not - for instance https://www.youtube.com/?gl=DE&tab=w11

 

Highlighted

@Thomas Höhner 

 

i had conifgured www.bitcoin.com, here's the result. 

clipboard_image_0.png

haven't tried the case you described but will try out as well and let you know the results .

 

 

 

 

 

 

Highlighted

@Thomas Höhner 

We are working to support this case as well.

Please read through the following documentation section.
Full URL path blocks can be applied on the domain level and all unencrypted URLs.

 

Highlighted

@Efrat Kliger - Hi having the same issue, URL indicators look correct but blocking stopped working in IE/Chrome and only intermittently blocks in Edge.  Have raised a support request w/MS. If anyone has insight on root cause would appreciate feedback  

Highlighted

@Scott650

Hi Scott,

I assume you're talking about the https related deep links, which are not blocked by CI as "expected" - from my understanding this is currently by design, as mdatp does not act as "man in the middle" breaking up the encrypted channel between the browser and the related webserver. Thus the only way to block https related URLs is to configure the related CI for the domain in general:

working : https://www.google.com

not working: https://www.google.com/whatever-deep-link

Highlighted

@Thomas Höhner 

Hi,

     Simply marked Zoom as unsanctioned in MCAS, worked for ~3 week and the just stopped.

Allowed the integration between MCAS and Defender ATP to automatically create the indicator.

Highlighted

@Scott650 Hi - determined that someone unlinked a GPO that enforced network protection.  The reason Edge worked was due to smartscreen. The Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection\EnableNetworkProtection=1  did not exist.

 

that was our root cause - hope this helps others

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/enable-ne...