Windows 10: Windows Defender ATP ExploitGuard False Web Block.

Discus and support Windows Defender ATP ExploitGuard False Web Block. in AntiVirus, Firewalls and System Security to solve the problem; Hi all, I'm trying to figure out how to either report a false block to Microsoft, or whitelist a website that was blocked. Your IT administrator... Discussion in 'AntiVirus, Firewalls and System Security' started by David Sto, Feb 4, 2019.

  1. David Sto Win User

    Windows Defender ATP ExploitGuard False Web Block.


    Hi all,


    I'm trying to figure out how to either report a false block to Microsoft, or whitelist a website that was blocked.


    Your IT administrator has caused Windows Defender Exploit Guard to block a potentially dangerous network connection.
    Detection time: 2019-02-04T19:37:31.935Z
    User: S-1-5-21-11****
    Destination: http://*websitehere*.com
    Process Name: C:\Program Files\Mozilla Firefox\firefox.exe


    I have access to the web portal at https://securitycenter.windows.com/ I have gone in there and whitelisted the IP as this is the ONLY thing I could think of to whitelist the page, but this isn't working. I cannot find and kind of config file or GPO setting either, but that doesn't mean one doesn't exist.


    Searching the internet I can find no way to report the incorrect block and if I go into the help section in Security Center I do see a report option, but it won't let me do it from my work email, I have to use an old microsoft account that has no license, so for a SINGLE report, it says it will cost $499.


    If it matters, the website does come up clean in virustotal and other web scanners.


    Any help would be greatly appreciated!


    Thank you!

    :)
     
    David Sto, Feb 4, 2019
    #1
  2. Naresh_K Win User

    Defender ATP

    Hi,



    Thank you for writing to Microsoft Community Forums.



    Usually we do not suggest to disable Windows Defender feature, Windows Defender ATP protects endpoints from cyber threats; detects advanced attacks and data breaches, automates security incidents, and improves security posture. However, if you
    still wish to disable it, please follow the steps mentioned below and check if it helps:

    1. Open Windows Settings (Windows key + I).
    2. Then click on Updates & Settings.
    3. Then click on Windows Security.
    4. You can disable Cloud based and automatic submissions.

    If you need any additional assistance, then please write back with the following information:

    1. What is the exact error message which you are getting?
    2. Is the issue specific to an application?
    3. Could you please
      post a screenshot for a better understanding?


    Regards,
     
    Naresh_K, Feb 4, 2019
    #2
  3. Windows Defender ATP.

    Why isn't the Windows Defender ATP platform available with Windows 10 Pro for free? What's the difference between Windows Defender and Windows Defender ATP? If you're going to make Windows 10 the best operating system ever, the virus and malware protection
    has to be the best too. So having one Windows Defender ATP across the whole Windows 10 ecosystem for free is better then having two different virus and malware platforms?
     
    AnthonyPosi, Feb 4, 2019
    #3
  4. Windows Defender ATP ExploitGuard False Web Block.

    Windows Defender ATP.

    Windows Defender ATP isn't protection, rather it's more after the fact forensics. Any sized firm can run ATP as you can enable it on Windows 10 pro with merely a script. What you have to have is a Windows E5 subscription license which now is sold in single
    units by cloud service providers.

    The naming of "Windows defender ATP" is IMHO a bad marketing name. It doesn't defend. It reports. It helps an admin understand when intrusions take place what IP the workstation talked to and what may have occurred but it still takes a technical person
    to interpret the findings.
     
    Susan Bradley - volunteer here not a MS employee, Feb 4, 2019
    #4
Thema:

Windows Defender ATP ExploitGuard False Web Block.

Loading...
  1. Windows Defender ATP ExploitGuard False Web Block. - Similar Threads - Defender ATP ExploitGuard

  2. Duplicate entries in Defender ATP

    in AntiVirus, Firewalls and System Security
    Duplicate entries in Defender ATP: Hello,Thanks in advance for any information on this issue.As you can see we have duplicate entries in the Security Center showing up. In the below example, there are 4 total entries for this VM. These VMs are deployed through a pipeline. For some reason some are showing up in...
  3. Windows Defender ATP service

    in Windows 10 Customization
    Windows Defender ATP service: Favor de ver este error cuando intento hacer un onboarding del WATPC:\WINDOWS\system32>%userprofile%\Desktop\WindowsDefenderATPLocalOnboardingScript This script will onboard this machine to the Windows Defender ATP service. Once completed, the machine should light up in the...
  4. Defender ATP iOS blocking Sonos App

    in AntiVirus, Firewalls and System Security
    Defender ATP iOS blocking Sonos App: Whenever i have the Microsoft Defender ATP app running on mu iOS device, it blocks access to external services such as radio and library functions. if disable the ATP vpn, it works as expected. how can we whitelist apps and services?...
  5. Defender ATP Analysis

    in AntiVirus, Firewalls and System Security
    Defender ATP Analysis: Is the analysis ie alerting and blocking happening on the endpoints laptops, desktops or in the ATP Cloud console? If the analysis is occurring on the endpoints, will it cause performance issues on all endpoints if it is deployed across ~15,000 devices? If that's the case,...
  6. Windows Defender ATP Reboot

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP Reboot: I am having an issue with Windows Defender ATP on all my Windows 10, domain joined PCs. After running the on-boarding script, the registry is updated at HKLM\SYSTEM\CurrentControlSet\Control\SessionManager\PendingFileRenameOperations with a number of ATP files. After a...
  7. Windows Defender ATP Offboarding

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP Offboarding: Need help with Offboarding 1000 Windows 10 devices from an old 2017 Trial ATP tenant no longer active. Any help would be grateful https://answers.microsoft.com/en-us/windows/forum/all/windows-defender-atp-offboarding/a3c0d30e-5c4a-4cd6-9947-6f0ee8e9311d"
  8. Defender ATP

    in AntiVirus, Firewalls and System Security
    Defender ATP: I tried to submit a question, but it would not let me submit it. What good does it do to have this system if it won't work. Why am I, as an individual home computer user, subject to the strict regulations of Defender ATP? I cannot connect to links that are provided in...
  9. Windows Defender ATP

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP: What is Sandbox in Windows Defender ATP? https://answers.microsoft.com/en-us/protect/forum/all/windows-defender-atp/714d1096-97e9-49bb-b825-c2c732ccd642
  10. Windows Defender ATP partnering w/ industry to reduce false positives

    in Windows 10 News
    Windows Defender ATP partnering w/ industry to reduce false positives: Every day, antivirus capabilities in Windows Defender Advanced Threat Protection (Windows Defender ATP) protect millions of customers from threats. To effectively scale protection, Windows Defender ATP uses intelligent systems that combine multiple layers of machine learning...