Microsoft Defender for Endpoint
Endpoint protection

Manage device scope and relevance with tags and exclusions

In brief

The page now clarifies that excluded devices may take up to 10 hours to disappear from vulnerability management data, while restored data may take up to 8 hours to reappear after exclusion stops.

What Defender admins need to know

Administrators should allow these processing windows when managing device exclusion scope.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage device scope and relevance with tags and exclusions

Exclude multiple devices

To exclude multiple devices at once, complete the following steps:

  1. In the Device inventory, select multiple devices using the checkboxes.

:::image type="content" source="media/exclude-device-bulk.png" alt-text="Screenshot of bulk device exclusion showing multiple selected devices.":::

To exclude multiple devices at once, complete the following steps:

  1. In the Device inventory, select multiple devices using the checkboxes.

:::image type="content" source="media/exclude-device-bulk.png" alt-text="Screenshot of bulk device exclusion showing multiple selected devices.":::

View and manage excluded devices

To view excluded devices in the inventory, use the following steps:

Stop excluding a device

To restore a device to active vulnerability management:

  1. In the Device inventory, select the excluded device.

:::image type="content" source="media/exclusion-details.png" alt-text="Screenshot showing exclusion details with option to stop exclusion.":::

Next steps