The "Isolate or Unisolate device on Microsoft Defender for Endpoint" workflow template is designed to streamline endpoint security management within an organization. Using either the `machineId` or `computerDnsName`, security teams can quickly isolate or reverse isolation on devices within their network to manage threats. It ensures the actions are successful, monitors endpoints, and compiles a history of previous isolations, enhancing the Endpoint Detection and Response (EDR) operations. Essential for maintaining secure and controlled network environments.
Optional Triggers
["This workflows is intended to be used as a function."]
Use Cases
Endpoint Detection and Response (EDR) , Function
Workflow Breakdown
Takes as an input machineId or computerDnsName values.
Submits Isolate or Unisolate action to device by it's machineId.
Workflow will wait an specified period of time to verify the action is successful applied by Endpoint.
Collects a list of previous Isolate or Unisolate actions.
Vendors
Utils, Microsoft Defender for Endpoint
Workflow Output
Summary of status of the action.