Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure Stop and Quarantine File capability in Microsoft Defender for Endpoint

Stop and quarantine files from the Microsoft Defender platform.

Before you begin

Supported Observable Types: SHA1 hash.

InputDescription
Comment(Required: Comment to associate with the action)

Role required: sn_si.admin or sn_si.analyst

About this task

You can run the Stop and Quarantine File action on the particular observables of type SHA1 only. Store the details on the Additional Actions on Endpoint table. You can trigger the Stop and Quarantine File capability from the Microsoft Defender for Endpoint Related Machines details related list.

Procedure

  1. Navigate to Security Incidents > Show All Incidents.

  2. Select the security incident that you want to review with the Microsoft Defender for Endpoint information.

  3. In the related links section, click Show All Related Lists.

  4. Click the Microsoft Defender for Endpoint Related Machines Details related list.

  5. Select one or more records.

  6. From the Actions on selected rows, select the Stop and Quarantine File capability.

  7. Validate the automation activity and activities section.

  8. View the data, and validate the data on the related lists.

  9. View the automation activities of the execution, and validate them.

Parent Topic:Additional Configurations in Microsoft Defender for Endpoint

Related topics

Configure Isolate Host capability in Microsoft Defender for Endpoint

Configure Remove Host Isolation capability in Microsoft Defender for Endpoint

Configure Run Antivirus Scan capability in Microsoft Defender for Endpoint

Configure Restrict App Execution capability in Microsoft Defender for Endpoint

Configure Remove App Restriction capability in Microsoft Defender for Endpoint

Configure Get Related Machines from Defender Capability in Microsoft Defender for Endpoint