Isolate Or Release Device
Isolate this device.
Last updated
Was this helpful?
Isolate this device.
This runbook isolates a device in Microsoft Defender for Endpoint to reduce the risk of lateral movement and data exfiltration. Optionally, it can release a previously isolated device. Provide a short reason so the action is documented in the service.
Device → Security → Isolate Or Release Device
Full Runbook name
rjgit-device_security_isolate-or-release-device
Type: WindowsDefenderATP
Machine.Read.All
Machine.Isolate
The device ID of the target device.
Required
true
Default Value
Type
String
"Isolate Device" (final value: false) or "Release Device from Isolation" (final value: true) can be selected as action to perform. If set to false, the runbook will isolate the device in Defender for Endpoint. If set to true, it will release a previously isolated device from isolation in Defender for Endpoint.
Required
true
Default Value
False
Type
Boolean
The isolation type to use when isolating the device.
Required
false
Default Value
Full
Type
String
A short reason for the (un)isolation action.
Required
true
Default Value
Possible security risk.
Type
String
Last updated
Was this helpful?
Was this helpful?