Issue with Web Content Filtering – Indicators Not Working

Mountain Pond 1,481 Reputation points
2025-01-18T01:27:17.23+00:00

Hello,

I'm trying to set up site blocking using Web Content Filtering. After enabling all the necessary components in Advanced Features in security center:

Web Content Filtering

And configuring the following components in the system (via Intune):

SmartScreen for apps and files

Allow Behavior Monitoring = Allowed (Enables real-time behavior monitoring)

Allow Cloud Protection = Allowed (Enables Cloud Protection)

msedge_GLNzkBWhEs

msedge_e9ZVZ06WOH

The "Web-based Email" blocking policy works as expected. However, it also blocks outlook.com, so I added an exception in Indicators. Additionally, I added youtube.com and tiktok.com to the blocked sites for testing.

msedge_VgiGDvIXi1

msedge_vPgKkjaMSm

vmconnect_wQ71XaJzUI

The issue is that Web Content Filtering works, but the Indicators do not seem to take effect.

Checked the requirements

https://learn.microsoft.com/en-us/defender-endpoint/indicator-ip-domain

Microsoft Defender Antivirus version requirements

  1. Your organization uses Microsoft Defender Antivirus. Microsoft Defender Antivirus must be in active mode for non-Microsoft browsers. With Microsoft browsers, like Microsoft Edge, Microsoft Defender Antivirus can be in active or passive mode.
  2. Behavior Monitoring is enabled.
  3. Cloud-based protection is turned on.
  4. Cloud Protection network connectivity is turned on.
  5. The anti-malware client version must be 4.18.1906.x or later. See Monthly platform and engine versions.
  6. Behavior Monitoring is enabled

User's image

  1. Cloud-based protection is turned on.

User's image

Changed 1 to 3 (SendAllSamples)

  1. Cloud Protection network connectivity is turned on.

User's image

  1. The anti-malware client version must be 4.18.1906.x or later

User's image

Could you please advise what might be causing this issue and how I can debug it?

Thank you.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,504 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
457 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,446 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.