cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Microsoft Defender Outbound traffic policy

L3 Networker

Trying to slim down a rule for outbound traffic with clients using MS defender. I built a custom URL list of the defender urls provided by MS. Added it to the policy under service/url category. The apps used are ms-update, ssl, web-browser, windows-defender-atp.

 

The issue is I see traffic hitting ssl in the logs with url category as "any" which means the process order must be left to right in the policy. 

 

source

destination

app

service/url category

 

So my assumption is once the rule sees SSL as the app it allows the traffic? Is this correct?

Who Me Too'd this topic