Skip to content

Document AlertAndBlock action and clarify GenerateAlert mapping - #504

Open
Jong Sabu (jongABCDsudo-rm-rf) wants to merge 4 commits into
MicrosoftDocs:publicfrom
jongABCDsudo-rm-rf:docs-indicator-alertandblock
Open

Document AlertAndBlock action and clarify GenerateAlert mapping#504
Jong Sabu (jongABCDsudo-rm-rf) wants to merge 4 commits into
MicrosoftDocs:publicfrom
jongABCDsudo-rm-rf:docs-indicator-alertandblock

Conversation

@jongABCDsudo-rm-rf

Copy link
Copy Markdown

Adds documentation for the AlertAndBlock action value supported by the Indicators API and clarifies its relationship to the existing BlockAndRemediate action and GenerateAlert parameter.

Indicators API accepts AlertAndBlock as a valid value for the action parameter, but it isn't listed in the supported parameters table on this page. Customers importing IoCs via CSV or calling the API directly currently have no documented reference for this value.

Functionally, AlertAndBlock on the API is equivalent to submitting action=BlockAndRemediate together with GenerateAlert=True. Seen in the Microsoft Defender portal, inputs render identically as Block and remediate with the Generate alert checkbox ticked.

@prmerger-automator

Copy link
Copy Markdown
Contributor

Jong Sabu (@jongABCDsudo-rm-rf) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit b8efdfd:

✅ Validation status: passed

File Status Preview URL Details
defender-endpoint/indicator-manage.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit fc88a5f:

✅ Validation status: passed

File Status Preview URL Details
defender-endpoint/indicator-manage.md ✅Succeeded

For more details, please refer to the build report.

@v-dirichards

Copy link
Copy Markdown
Contributor

Limor Wainstein (@limwainstein)

Can you review the proposed changes?

Important: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator Bot added the aq-pr-triaged Tracking label for the vendor PR Review team label Jul 8, 2026
@prmerger-automator

Copy link
Copy Markdown
Contributor

Jong Sabu (@jongABCDsudo-rm-rf) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the Manage indicators documentation to include the AlertAndBlock action for indicator imports/API usage and explain how it relates to existing action/alert settings.

Changes:

  • Added AlertAndBlock to the supported action values list.
  • Clarified how AlertAndBlock relates to BlockAndRemediate and alert generation.

Comment thread defender-endpoint/indicator-manage.md Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit e30ac46:

❌ Validation status: errors

Please follow instructions here which may help to resolve issue.

File Status Preview URL Details
❌Error Details

  • [Error: CannotMergeCommit] Cannot merge commit e30ac46f41c38d5a44ae9449ff57c6b5366ec9c1 in branch docs-indicator-alertandblock of repository https://github.com/jongABCDsudo-rm-rf/defender-docs into branch public (commit e8a91d1b3c934e3a00cce0a21ddd2959601f4c10). Please follow this documentation: https://help.github.com/articles/resolving-a-merge-conflict-using-the-command-line/ to use git.exe to resolve you content conflicts locally and then push to remote.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit d7174ef:

✅ Validation status: passed

File Status Preview URL Details
defender-endpoint/indicator-manage.md ✅Succeeded

For more details, please refer to the build report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants