Skip to main content
Create or update a new indicator entity. The following permissions are required to run this action:
  • Ti.ReadWrite
  • Ti.ReadWrite.All
External DocumentationTo learn more, visit the Microsoft Defender for Endpoint documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Create or Update Indicator with Microsoft Defender for Endpoint and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop