logo

Microsoft Defender can now automatically isolate hacked endpoints

ID: f8d19fd7-62c6-5ec6-acfa-c0f21de4902d

STIX ID: report--f8d19fd7-62c6-5ec6-acfa-c0f21de4902d

Feed Name: Bleeping Computer

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Sergiu Gatlan

...
...

Microsoft is previewing an automatic device isolation capability in Defender for Endpoint that disconnects suspected compromised endpoints from the network (while retaining connectivity to Defender for monitoring) to limit lateral movement and impact. The article also reviews related Defender features and testing milestones—manual containment, Linux support, account isolation, blocking traffic to undiscovered endpoints, and scheduled Linux scans—and explains how admins can release devices from isolation after investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.