Web protection
MDE web protection is a defense mechanism against web-based threats and a content filter. It has robust TI, enhancing your metadata around URLs and access trends so that you can understand what might need to be blocked within your ecosystem.
The following components, listed in order of precedence, together make up the web protection category. They are enforced by the SmartScreen client in the Microsoft Edge browser, and by the Network Protection client in all other browsers or processes:
- Custom indicators of compromise (IoCs)
- Web threat protection (WTP)
- Web content filtering (WCF)
- Microsoft Defender for Cloud Apps (MDCA) allow
Based on this precedence order, a URL or IP address is evaluated. This means that, for example, custom IP or URL indicators can override a WCF policy since they are higher in the order of precedence.
When there is a conflict in the preceding list, allows always take precedence over blocks (override logic), meaning...