Additional Configurations in Microsoft Defender for Endpoint
The Microsoft Defender for Endpoint integration supports running additional actions beyond the standard actions.
The Microsoft Defender for Endpoint supports the following additional configurations:
- Configure Isolate Host capability in Microsoft Defender for Endpoint
Isolate the host from accessing the network in Microsoft Defender for Endpoint based on the severity of the attack. Isolating the host from the network enables you to prevent any other malicious activities or potential attacks on other hosts. - Configure Remove Host Isolation capability in Microsoft Defender for Endpoint
If needed, remove the isolation of a host that was previously isolated from the network in Microsoft Defender for Endpoint. You can prevent any other malicious activities or potential attacks on other hosts. - Configure Run Antivirus Scan capability in Microsoft Defender for Endpoint
Remotely initiate an anti virus scan to help identify and remediate malware that might be present on a compromised device. Run the scan as part of the investigation or response process. - Configure Restrict App Execution capability in Microsoft Defender for Endpoint
To contain an attack, restrict or lock a device and prevent subsequent attempts of potentially malicious programs from running. - Configure Remove App Restriction capability in Microsoft Defender for Endpoint
If needed, remove the restrictions of any application on the device. - Configure Get Related Machines from Defender Capability in Microsoft Defender for Endpoint
Get the list of related machines of specific observables. - Configure Stop and Quarantine File capability in Microsoft Defender for Endpoint
Stop and quarantine files from the Microsoft Defender platform.
Parent Topic:Microsoft Defender for Endpoint integration