Microsoft Defender Introduces Automatic Isolation for Compromised Devices

Microsoft Defender Introduces Automatic Isolation for Compromised Devices

First seen 26 May 2026, 14:44 UTC BleepingcomputerCybersecuritynewsFeeds.FeedburnerCsoonlineItnews.Au+6 90% similarity 42.9

Article Content

Browse articles
ThreatCluster

Microsoft has launched a new feature in Defender for Endpoint that automatically isolates compromised devices to prevent lateral movement by attackers. This capability, currently in preview, disconnects affected endpoints from the network while maintaining monitoring connectivity. The automatic isolation feature is part of the Automatic Attack Disruption framework, which aims to contain attacks and provide security teams with additional response time. This functionality is limited to onboarded end-user workstations managed by Microsoft Defender for Endpoint. Security operators can release isolated devices after risk mitigation and investigation. Previous enhancements included manual containment for unmanaged devices and isolation support for Linux systems. The feature is designed to help mitigate risks such as data exfiltration and ransomware propagation. Microsoft has also been testing additional features to enhance network security further.

Key Points: • Microsoft Defender can now automatically isolate compromised devices to limit attack spread. • The feature is currently in preview and applies to onboarded end-user workstations. • Security teams can release devices from isolation after completing investigations.

ThreatCluster AI

Timeline

2022-06-01
Manual containment for unmanaged devices announced
Microsoft introduced a feature allowing admins to manually isolate unmanaged Windows devices.
BleepingComputer
2023-01-01
Device isolation support for Linux introduced
Microsoft began testing device isolation for Linux endpoints as part of Defender for Endpoint.
BleepingComputer
2023-10-01
Linux isolation feature reaches general availability
The isolation feature for Linux devices became generally available, enhancing security for these systems.
BleepingComputer
2023-10-01
Isolation of compromised user accounts announced
Microsoft revealed the capability to isolate compromised user accounts to prevent lateral movement in ransomware attacks.
BleepingComputer
2026-05-26
Automatic isolation feature launched in preview
Microsoft Defender for Endpoint's automatic isolation feature was announced, aimed at containing attacks proactively.
BleepingComputer

Community

Browse all →