Microsoft Defender for Endpoint
Endpoint protection

Evaluate Network Protection

In brief

The article now says to use Event Viewer and filter for Event ID 1125 to review blocked apps, and specifies that the prerequisite guidance applies when malicious sites are not detected. The publication date and custom metadata were also updated.

What Defender admins need to know

Administrators have clearer guidance for reviewing blocked applications and troubleshooting malicious-site detection.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review network protection events in Windows Event Viewer

To review apps that would have been blocked,blocked apps, open Event Viewer and filterViewer. Filter for Event ID 1125 in the Microsoft-Windows-Windows Defender/Operational log. The following table lists all network protection events.

Event ID Provide/Source Description

Troubleshooting Network Protection

If network protection fails to detect,detect malicious sites, make sure that the following prerequisites are enabled:

  1. Microsoft Defender Antivirus is the primary antivirus app (active mode)