Bleepingcomputer
Microsoft Defender Introduces Automatic Isolation for Compromised Devices
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has launched a new feature in Defender for Endpoint that automatically isolates compromised devices to prevent lateral movement by attackers. This capability, currently in preview, disconnects affected endpoints from the network while maintaining monitoring connectivity. The automatic isolation feature is part of the Automatic Attack Disruption framework, which aims to contain attacks and provide security teams with additional response time. This functionality is limited to onboarded end-user workstations managed by Microsoft Defender for Endpoint. Security operators can release isolated devices after risk mitigation and investigation. Previous enhancements included manual containment for unmanaged devices and isolation support for Linux systems. The feature is designed to help mitigate risks such as data exfiltration and ransomware propagation. Microsoft has also been testing additional features to enhance network security further.
Key Points: • Microsoft Defender can now automatically isolate compromised devices to limit attack spread. • The feature is currently in preview and applies to onboarded end-user workstations. • Security teams can release devices from isolation after completing investigations.