Microsoft Defender for Cloud Apps
Cloud and workloads

Work with IP ranges and tags

In brief

The article now more clearly describes defining IP ranges, assigning categories and custom tags, using built-in tag IDs, and creating tags. It also updates terminology, metadata, and image alt text.

What Defender admins need to know

Administrators can use the revised guidance to configure and manage IP tags more easily. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Work with IP ranges and tags

To easily identify known IP addresses, such as your physical office IP addresses, you need to set IP address ranges. IP address ranges allow you to tag, categorize, and customize the way logs and alerts are displayed and investigated. Each group of IP ranges can be categorized based on a preset list of IP categories. You're also able to create custom IP tags for your IP ranges. Additionally, you can override public geolocation information based on your internal network knowledge. Both IPv4 and IPv6 are supported.

Defender for Cloud Apps comes preconfigured with built-in IP ranges for popular cloud providers such as Azure and Microsoft 365. Additionally, we have built-in tagging based on Microsoft threat intelligence including anonymous proxy, Botnet, and Tor. You can see the full list of built-in IP tags in the drop-down on the IP address ranges page.

- **VPN**: These IPs should be any IP addresses you use for remote workers. By using this category, you can avoid raising [impossible travel](anomaly-detection-policy.md#impossible-travel) alerts when employees connect from their home locations via the corporate VPN.

To include the IP range in a category, select a category from the **Categories** drop-down menu.
  1. To Tag the activities from these IP addresses enter a tag. Entering a word into the box creates the tag. After you already havecreate a configured tag, you can easily add itthat tag to additional IP ranges by choosing itselecting the tag from the existing tags list. You can add more than one IP tag for each range. IP tags can be used when building policies. Along with IP tags you configure, Defender for Cloud Apps has built-in tags that aren't configurable. You can see the list of built-in IP tags under the IP tags filter.
  1. When you're done, select Create.

    Screenshot showing the dialog to create a new IP address range in Defender for Cloud Apps.

Next steps