Microsoft Defender can now automatically isolate compromised devices during a cyberattack, helping security teams stop threats faster without manual intervention.
If Defender detects a compromised device, it cuts the device off from the network automatically while still allowing remote investigation and remediation.
This prevents attackers from spreading across the network, stealing data, or deploying ransomware.
The new feature is part of Microsoft’s focus on automated threat response in Defender XDR.
Security tools now take real-time action beyond detection and alerts to limit damage:
>Automatically isolates compromised devices
>Helps stop ransomware and lateral movement
>Security teams retain remote access for investigation
>Currently available as a preview in Microsoft Defender for Endpoint