Microsoft lets Defender automatically isolate infected PCs

TL;DR AI
2 min readKey summary
Microsoft is previewing an automatic isolation feature in Defender for Endpoint that can cut suspicious workstations off from internal network traffic.
The quarantined device still keeps cloud connectivity, letting security teams investigate and respond remotely through the Defender portal.
Administrators can restore access after review, and the capability is part of Microsoft’s broader automatic attack disruption strategy.
The goal is to slow attackers, limit lateral movement, and reduce ransomware spread before manual containment is needed.
