If needed, remove the isolation of a host that was previously isolated from the
network in Microsoft Defender for Endpoint. You can prevent any other malicious
activities or potential attacks on other hosts.
Before you begin
Table 1. Requirements for Remove Isolation capability
| Capability |
Required Input |
Description |
| Remove Isolation |
Comment |
(Required) Comment to associate with the action. |
Role required: sn_si.admin or sn_si.analyst
Procedure
-
Navigate to .
-
Select the security incident that you want to review with the Microsoft
Defender for Endpoint information.
-
In the Related Links section, select Run EDR Profile(s).
-
Browse and select a profile with Remove Isolation capability selected from the list of available profiles, and select Submit.
Alternatively, you can perform the following steps:
- Select Show All Related Lists in the related lists section.
- Select the Configuration Item related list.
- Select Remove Isolation and select the corresponding capabilities.
-
Validate the automation activity and activities section.
-
View the data, and validate the isolate host details on the related
lists.
-
Validate the automation activities of the execution.