Microsoft Defender for Endpoint
Endpoint protection

Manage automation file uploads in Microsoft Defender for Endpoint

In brief

The article title and wording were updated, including a more specific description of cloud-based file inspection and the **Content analysis** setting label. Metadata was also refreshed.

What Defender admins need to know

Administrators can use the updated terminology when locating and following this guidance; no action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage automation file uploads in Microsoft Defender for Endpoint

Enable the content analysis capability so that certain files and email attachments can automatically be uploaded to the cloud for additional inspection in Automated investigation.

Microsoft uses variouscloud-based file investigationinspection mechanisms to inspect and analyze files.

Identify the files and email attachments by specifying the file extension names and email attachment extension names.

  1. In the navigation pane, select Settings > Endpoints > Rules > Automation uploads.

  2. Toggle the contentContent analysis setting between On and Off.

  3. Configure the following extension names and separate extension names with a comma: