Configure Remove Host Isolation capability in Microsoft Defender for Endpoint
릴리스 버전: Australia
업데이트 날짜 2026년 03월 12일
소요 시간: 2분
If needed, remove the isolation of a host that was previously isolated from the
network in Microsoft Defender for Endpoint. You can prevent any other malicious
activities or potential attacks on other hosts.
시작하기 전에
표 1. Requirements for Remove Isolation capability
Capability
Required Input
Description
Remove Isolation
Comment
(Required) Comment to associate with the action.
Role required: sn_si.admin or sn_si.analyst
프로시저
Navigate to Security Incidents > Show All Incidents.
Select the security incident that you want to review with the Microsoft
Defender for Endpoint information.
In the Related Links section, click Run EDR
Profile(s).
Browse and select a profile with Remove Isolation
capability selected from the list of available profiles, and
click Submit.
그림 1. Remove Isolation
Alternatively, you can perform the following steps:
Click Show All Related Lists in the related
lists section.
Click the Configuration Item related
list.
Select Remove Isolation and select the
corresponding capabilities.
Validate the automation activity and activities section.
View the data, and validate the isolate host details on the related
lists.
Validate the automation activities of the execution.