Microsoft adds automatic isolation of infected devices to its endpoint security products

TL;DR AI
2 min readKey summary
Microsoft has added a preview feature to Defender for Endpoint that automatically isolates suspicious devices from the corporate network while preserving cloud access for remote investigation.
The capability is part of Microsoft’s automatic attack disruption program and is designed to slow attacker movement before ransomware deployment or data theft.
It currently works only on enrolled workstations, extending earlier manual isolation and related endpoint protections.



