To contain an attack, restrict or lock a device and prevent subsequent attempts of
potentially malicious programs from running.
Before you begin
Table 1. Requirements for Restrict App Execution capability
| Input |
Description |
| Comment |
(Required) Comment to associate with the action) |
Role required: sn_si.admin or sn_si.analyst
Procedure
-
Navigate to .
-
Select the security incident that you want to review with
the Microsoft Defender for Endpoint information.
-
In the related links section, click .
-
Browse and select the Restrict App Execution
capability.
Figure 1. Restrict App Execution
Alternatively, you can perform the following steps:
- In the related lists section, click Show All Related
Lists.
- Click the Configuration Item related
list.
- Select the added configuration items.
- From the Actions on selected rows, select Run Additional
Actions on Endpoint.
-
To enable Restrict App Execution on the machine, click Run
Additional Action.
-
View the automation activities of the execution, and validate them.
-
Validate the status of the action on the Additional Actions on Endpoint related
lists.