Switch language한국어
Back to the list

Microsoft adds automatic isolation of infected devices to its endpoint security products

TL;DR AI

Key summary

2 min read
  1. Microsoft has added a preview feature to Defender for Endpoint that automatically isolates suspicious devices from the corporate network while preserving cloud access for remote investigation.

  2. The capability is part of Microsoft’s automatic attack disruption program and is designed to slow attacker movement before ransomware deployment or data theft.

  3. It currently works only on enrolled workstations, extending earlier manual isolation and related endpoint protections.

Read the original