Automatic device isolation (automatic attack disruption)
Automatic device isolation (automatic attack disruption)
Microsoft Defender for Endpoint can now automatically isolate compromised devices as part of automatic attack disruption. Isolation blocks most network traffic while keeping the device connected to security services. The action is time-limited, scoped to the incident, and security operators can release isolation at any time.

