Switch language한국어
Back to the list

Microsoft lets Defender automatically isolate infected PCs

TL;DR AI

Key summary

2 min read
  1. Microsoft is previewing an automatic isolation feature in Defender for Endpoint that can cut suspicious workstations off from internal network traffic.

  2. The quarantined device still keeps cloud connectivity, letting security teams investigate and respond remotely through the Defender portal.

  3. Administrators can restore access after review, and the capability is part of Microsoft’s broader automatic attack disruption strategy.

  4. The goal is to slow attackers, limit lateral movement, and reduce ransomware spread before manual containment is needed.

Read the original