Feb 10 2023 01:14 AM
Hi - where in MS 365 Defender can I create a custom list of devices, that I can just update once and reference in multiple KQL queries?
I have looked in Settings - there is no option for Microsoft Defender for Endpoint lists.
Thanks for any help,
Mark
Feb 10 2023 09:10 AM
To create a custom list of devices in Microsoft Defender for Endpoint, you can use the Microsoft Defender Security Center. To do so, follow these steps:
Once the custom list is created, you can use it in multiple KQL queries by referencing the custom list in the query. To do so, use the following syntax:
DeviceList('<CustomListName>')
For example, if your custom list is named "ImportantDevices", the KQL query would be:
DeviceList('ImportantDevices')
Feb 10 2023 09:28 AM
Hi Robina - thank you for your reply.
When I select devices on the Devices page, I do not see "Add to custom list", I only see:
I've attached a screenshot.
Have I missed something, or is it perhaps that I don't have specific permissions to create custom lists?
Thanks again,
Mark
Feb 10 2023 09:37 AM
Feb 10 2023 09:40 AM
Solution@marktait19 It sounds like you're using a security or device management platform that may have different options available to you based on your account level or the type of device you have selected. "Add to custom list" is not a standard feature in all security or device management platforms, and its availability may vary.
If you're looking for specific information or functionality that is not available to you, I recommend reaching out to your platform's support team for assistance. They will be able to provide you with more information on the features and functionality that are available to you.
Feb 10 2023 09:43 AM
Feb 10 2023 09:40 AM
Solution@marktait19 It sounds like you're using a security or device management platform that may have different options available to you based on your account level or the type of device you have selected. "Add to custom list" is not a standard feature in all security or device management platforms, and its availability may vary.
If you're looking for specific information or functionality that is not available to you, I recommend reaching out to your platform's support team for assistance. They will be able to provide you with more information on the features and functionality that are available to you.