Microsoft Defender for Endpoint
Endpoint protection

Web protection in Microsoft Defender for Endpoint

In brief

The article metadata was refreshed and new introductory text now summarizes web threat protection, web content filtering, custom indicators, browser support, and policy precedence.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Web protection in Microsoft Defender for Endpoint

This article explains how web protection in Microsoft Defender for Endpoint helps secure your devices against web threats and regulate unwanted content. It covers the core capabilities—web threat protection, web content filtering, and custom indicators—along with browser support, policy precedence rules, troubleshooting, and advanced hunting queries. This information is intended for security administrators and IT professionals who manage Defender for Endpoint.

Overview

Advanced hunting for web protection

Kusto queries in advanced hunting can be used to summarize web protection blocks in your organization for up to 30 days. These queries use the response categories from the Troubleshoot endpoint blocks table to distinguish between the various sources of blocks and summarize them in a user-friendly manner. For example, to find WCFWeb Content Filtering (WCF) blocks detected by SmartScreen in Microsoft Edge, run the following query:query. This query filters DeviceEvents for SmartScreen URL warning actions and extracts key fields such as device name, timestamp, URL, and the experience category to identify web content filtering blocks.

DeviceEvents