{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
        "slug": "dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/"
        },
        "title": "Check the restoration scope before undoing a Defender false positive",
        "summary": "How can a quarantined-file restoration affect more than the single file an analyst intended to release?",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:10+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 258,
        "potentially_affected": "Windows Defender for Endpoint false-positive remediation and quarantined files.",
        "dse_recommendation": "Prefer an explicitly reviewed file-and-device restoration scope over an unexamined bulk undo.",
        "primary_source": {
            "name": "Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender&#8217;s Action center history supports undoing an eligible quarantine action for one file. The interface can also apply an undo to additional instances of that file. An unavailable Undo button indicates that the selected action cannot be reversed there; actions performed through live response cannot be undone. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Microsoft&#8217;s command-line CustomEnterpriseBlock restoration example is broader: its warning says it restores all custom-blocked files quarantined on that device during the preceding thirty days. The source also warns that a file quarantined as a potential network threat might not be recoverable. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This brief concerns Windows Defender for Endpoint false-positive remediation and quarantined files. Establish that the file is safe before choosing a restoration method. Restoring an artifact and changing future protection policy are separate decisions.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends starting with the completed action&#8217;s details and an explicit list of intended file instances and devices. Review any expanded instance selection before executing an undo. Do not translate one approved release into approval for every custom-blocked artifact from the same device. If restoration is unavailable, escalate with the original action and location evidence rather than repeatedly trying broader commands.</p>\n<h2>Verification</h2>\n<p>Check the action outcome and the intended file on each approved device. Compare the actual restoration scope with the approved list and investigate unexpected releases. Preserve the safety determination and action record together. Review any requested exclusion separately, so restoring a wrongly quarantined file does not silently become a permanent reduction in inspection.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Address Defender for Endpoint false positives and negatives</a>.</p>",
        "content_text": "Source facts\nDefender’s Action center history supports undoing an eligible quarantine action for one file. The interface can also apply an undo to additional instances of that file. An unavailable Undo button indicates that the selected action cannot be reversed there; actions performed through live response cannot be undone. Microsoft Learn.\nMicrosoft’s command-line CustomEnterpriseBlock restoration example is broader: its warning says it restores all custom-blocked files quarantined on that device during the preceding thirty days. The source also warns that a file quarantined as a potential network threat might not be recoverable. Microsoft Learn.\nApplicability\nThis brief concerns Windows Defender for Endpoint false-positive remediation and quarantined files. Establish that the file is safe before choosing a restoration method. Restoring an artifact and changing future protection policy are separate decisions.\nDSE recommendation\nDSE recommends starting with the completed action’s details and an explicit list of intended file instances and devices. Review any expanded instance selection before executing an undo. Do not translate one approved release into approval for every custom-blocked artifact from the same device. If restoration is unavailable, escalate with the original action and location evidence rather than repeatedly trying broader commands.\nVerification\nCheck the action outcome and the intended file on each approved device. Compare the actual restoration scope with the approved list and investigate unexpected releases. Preserve the safety determination and action record together. Review any requested exclusion separately, so restoring a wrongly quarantined file does not silently become a permanent reduction in inspection.\nOfficial references\nMicrosoft Learn: Address Defender for Endpoint false positives and negatives.",
        "content_markdown": "## Source facts\n\nDefender’s Action center history supports undoing an eligible quarantine action for one file. The interface can also apply an undo to additional instances of that file. An unavailable Undo button indicates that the selected action cannot be reversed there; actions performed through live response cannot be undone. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives).\n\nMicrosoft’s command-line CustomEnterpriseBlock restoration example is broader: its warning says it restores all custom-blocked files quarantined on that device during the preceding thirty days. The source also warns that a file quarantined as a potential network threat might not be recoverable. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives).\n\n## Applicability\n\nThis brief concerns Windows Defender for Endpoint false-positive remediation and quarantined files. Establish that the file is safe before choosing a restoration method. Restoring an artifact and changing future protection policy are separate decisions.\n\n## DSE recommendation\n\nDSE recommends starting with the completed action’s details and an explicit list of intended file instances and devices. Review any expanded instance selection before executing an undo. Do not translate one approved release into approval for every custom-blocked artifact from the same device. If restoration is unavailable, escalate with the original action and location evidence rather than repeatedly trying broader commands.\n\n## Verification\n\nCheck the action outcome and the intended file on each approved device. Compare the actual restoration scope with the approved list and investigate unexpected releases. Preserve the safety determination and action record together. Review any requested exclusion separately, so restoring a wrongly quarantined file does not silently become a permanent reduction in inspection.\n\n## Official references\n\n[Microsoft Learn: Address Defender for Endpoint false positives and negatives](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check the restoration scope before undoing a Defender false positive",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/",
                "headline": "Check the restoration scope before undoing a Defender false positive",
                "description": "How can a quarantined-file restoration affect more than the single file an analyst intended to release?",
                "abstract": "How can a quarantined-file restoration affect more than the single file an analyst intended to release?",
                "articleBody": "Source facts\nDefender’s Action center history supports undoing an eligible quarantine action for one file. The interface can also apply an undo to additional instances of that file. An unavailable Undo button indicates that the selected action cannot be reversed there; actions performed through live response cannot be undone. Microsoft Learn.\nMicrosoft’s command-line CustomEnterpriseBlock restoration example is broader: its warning says it restores all custom-blocked files quarantined on that device during the preceding thirty days. The source also warns that a file quarantined as a potential network threat might not be recoverable. Microsoft Learn.\nApplicability\nThis brief concerns Windows Defender for Endpoint false-positive remediation and quarantined files. Establish that the file is safe before choosing a restoration method. Restoring an artifact and changing future protection policy are separate decisions.\nDSE recommendation\nDSE recommends starting with the completed action’s details and an explicit list of intended file instances and devices. Review any expanded instance selection before executing an undo. Do not translate one approved release into approval for every custom-blocked artifact from the same device. If restoration is unavailable, escalate with the original action and location evidence rather than repeatedly trying broader commands.\nVerification\nCheck the action outcome and the intended file on each approved device. Compare the actual restoration scope with the approved list and investigate unexpected releases. Preserve the safety determination and action record together. Review any requested exclusion separately, so restoring a wrongly quarantined file does not silently become a permanent reduction in inspection.\nOfficial references\nMicrosoft Learn: Address Defender for Endpoint false positives and negatives.",
                "datePublished": "2026-09-10T00:30:10+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check the restoration scope before undoing a Defender false positive"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Playbook",
                    "Information priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 258,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives"
                }
            }
        ]
    }
}