Microsoft Sentinel
Cloud and workloads

Watchlists Manage

In brief

The documentation now says explicitly that uploading a file after removing items does not delete those items from the existing watchlist. It also updates the page metadata.

What Defender admins need to know

Administrators should individually delete removed items, or delete and recreate the watchlist when there are many deletions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

When you have many items to add to a watchlist, use bulk update. A bulk update of a watchlist appends items to the existing watchlist. Then, it de-duplicates the items in the watchlist where all the value in each column match.

If you've deleted an item from your watchlist file and upload it,the file, bulk update won't delete the item in the existing watchlist. Delete the watchlist item individually. Or, when you have a lot of deletions, delete and recreate the watchlist.

The updated watchlist file you upload must contain the search key field used by the watchlist with no blank values.