---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Update indicators

# Update indicators in Microsoft Defender for Endpoint {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Update the existing indicators in Microsoft Defender for Endpoint from the
list context-menu or from the form view of the Microsoft Defender Indicator
respectively.

## Antes de Iniciar

Role required: sn_si.admin, sn_si.analyst

## Procedimento

1. Navigate to Security IncidentsShow All Incidents.
2. Click Show All Related Lists and then click the Microsoft Defender Indicators tab.  
   Nota:  
   You must configure the related list for the Microsoft Defender
   Indicators, which would appear in the Security Incident related lists.
   For more information, see [Form UI
   actions](https://servicenow-prod.fluidtopics.net/1gzsswakDucNwVWZHMX_wA "You can configure the UI actions that are displayed in the Security Analyst Workspace.").
3. Update the Microsoft Defender for Endpoint indicators in one of the following ways:
   * To update the indicators from the list context-menu, select the row of the indicator that you want to update and click Update Indicator in the Microsoft Defender option.Figura 1. Update Indicators using list context-menu
   * To update the indicators from the form view, click Update Indicator in Microsoft Defender in the form view.Figura 2. Update Indicators using form view
4. On the form, fill in the fields.  
   {#update-indicator-in-microsoft-defender-for-endpoint-using-the-microsoft-defender-indicator-form-view__table_sx2_kbl_jsb__entry__2}

   | Field | Description |
   |-|-|
   | Title | Title for the indicator. |
   | Description | Description for the indicator. |
   | Expiration Time | Expiration time for the indicator. |
   | Recommended Actions | Recommended actions to be performed for the indicator. |
   | Source | Integration configuration to create the indicator. |
   | Action | Actions that are performed if the indicator is discovered in the organization. The possible values are as follows: * Warn * Block * Audit * BlockAndRemediate * Allowed {#update-indicator-in-microsoft-defender-for-endpoint-using-the-microsoft-defender-indicator-form-view__ul_bt1_l3c_rsb} |
   | Application | The Microsoft Defender for Endpoint application that is associated with the indicator. This field is applicable only for a new indicator and cannot be used for an existing indicator. |
   | Severity | Severity of the Indicator. Possible values are as follows: * Low * Medium * High {#update-indicator-in-microsoft-defender-for-endpoint-using-the-microsoft-defender-indicator-form-view__ul_tx2_kbl_jsb} |
   | RBAC Group Names | RBAC group names that the indicator is applied to. The names are in a comma-separated list. |
   [Tabela 1. Microsoft Defender Indicator form]

   {#update-indicator-in-microsoft-defender-for-endpoint-using-the-microsoft-defender-indicator-form-view__table_sx2_kbl_jsb}
5. Click Update Indicator.
6. Validate the activity and UI messages.

