Bleepingcomputer Microsoft Defender Introduces Automatic Isolation for Compromised Devices
Article Content
- •Microsoft Defender can now automatically isolate compromised devices to limit attack spread.
- •The feature is currently in preview and applies to onboarded end-user workstations.
- •Security teams can release devices from isolation after completing investigations.
Microsoft has launched a new feature in Defender for Endpoint that automatically isolates compromised devices to prevent lateral movement by attackers. This capability, currently in preview, disconnects affected endpoints from the network while maintaining monitoring connectivity. The automatic isolation feature is part of the Automatic Attack Disruption framework, which aims to contain attacks and provide security teams with additional response time. This functionality is limited to onboarded end-user workstations managed by Microsoft Defender for Endpoint. Security operators can release isolated devices after risk mitigation and investigation. Previous enhancements included manual containment for unmanaged devices and isolation support for Linux systems. The feature is designed to help mitigate risks such as data exfiltration and ransomware propagation. Microsoft has also been testing additional features to enhance network security further.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…