Microsoft Defender can now automatically isolate hacked endpoints
ID: f8d19fd7-62c6-5ec6-acfa-c0f21de4902d
STIX ID: report--f8d19fd7-62c6-5ec6-acfa-c0f21de4902d
Feed Name: Bleeping Computer
Microsoft is previewing an automatic device isolation capability in Defender for Endpoint that disconnects suspected compromised endpoints from the network (while retaining connectivity to Defender for monitoring) to limit lateral movement and impact. The article also reviews related Defender features and testing milestones—manual containment, Linux support, account isolation, blocking traffic to undiscovered endpoints, and scheduled Linux scans—and explains how admins can release devices from isolation after investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
