AI & Enterprise
Microsoft adds automatic isolation of infected devices to endpoint security product
Microsoft has added an automatic device isolation feature to its Defender for Endpoint platform. When suspicious activity is detected, the feature blocks the endpoint from the corporate network while keeping its connection to the Microsoft cloud so security teams can investigate remotely. It is offered as a preview and works only on workstations registered with Defender for Endpoint. Microsoft introduced it under its automatic attack disruption programme.