Microsoft Defender for Endpoint
Endpoint protection

Machine Tags

In brief

The article now directs admins to select devices from file and IP address views and delete tags from the device page.

What Defender admins need to know

The revised steps clarify where to manage device tags in the Defender portal.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Add device tags using the portal

To add tags to a device in the Defender portal, follow these steps:

  1. Select the device that you want to manage tags on. You can select or search for a device from any of the following views:

    • Alerts queue - Select the device name beside the device icon from the alerts queue.

    • Devices inventory - Select the device name from the list of devices.

    • Search box - Select Device from the drop-down menu and enter the device name.

      You can also get to the alert page throughselect a device from the file and IP address views.

  2. Select Manage tags from the row of Response actions.

When you create a new tag, a list of existing tags is displayed. The list only shows tags created through the portal. Existing tags created from client devices aren't displayed.

You can also delete tags from this view.the device page.

:::image type="content" source="media/new-tag-label-display.png" alt-text="Adding tags on device2" lightbox="media/new-tag-label-display.png":::