Isolation & Live Response | Microsoft Defender for Endpoint

preview_player
Показать описание
Learn how to use Defender for Endpoint’s Isolation and Live Response features to better improve your investigations by restricting the potential lateral movement of a compromised device across your network.

Live response gives security teams immediate access to a device using a remote shell connection. This gives you the power to do in-depth investigative work and take immediate response actions to promptly contain identified threats in real time. Live response is designed to enhance investigations by enabling your security operations team to collect forensic data, run scripts, send suspicious entities for analysis, remediate threats, and proactively hunt for emerging threats.

Want more hands on advice to help you get the most out of Microsoft 365 Defender? Sign up for our no-cost, no-obligation, Microsoft 365 Defender Advisory Service to get a one-to-one consultation with our award-winning Microsoft Security experts.

Follow Us on Linkedin
Рекомендации по теме
Комментарии
Автор

Can we do for restart and shutdown a device for defender for endpoint using live response

sunkuvenkataganeshkumar
Автор

How do you change the information shown on the pop-up notification the end user get when the device gets isolated?
For us the only thing the user sees is a notification telling them that an administrator has isolated the device.
Would be sweet to customize that message with information/instructions for the end user

jirayahatake
Автор

Hello, could you please advise on this, actually we isolate a device and the status will stay pending. Status just says “Action is pending for completion” and "Release from isolation" is grayed out.

dpkseth
Автор

how to switch to other drives when on live response? it seems that theres only C: drive?

sscoconut
Автор

I isolated the VM, but I want to access it using RDP but isolation blocks everything, can you please tell me how can I enable RDP?

shitalpatil