Defender XDR isolates devices automatically in 128 seconds

Microsoft is extending automatic attack disruption in Defender XDR with a new response action. When the system identifies a compromised workstation as an active attack foothold with high confidence, it can isolate the device from the network automatically. In an incident documented by Microsoft at QNET, only 128 seconds passed between the first detection and completed isolation. Automatic device isolation is currently in preview.

What automatic device isolation does

Defender XDR does not assess a single alert in isolation. Automatic attack disruption correlates signals from endpoints, identities, email, applications, and other Defender services into one incident. Defender initiates isolation only after the attack chain has been identified with high confidence and a device has been established as an active foothold. Microsoft states that the underlying containment decisions maintain a precision of 99 percent.

  • The affected workstation loses most internal and external network connectivity.
  • Connectivity to the required Microsoft Defender for Endpoint security services remains available.
  • The security team receives an already contained incident and can continue investigation and remediation in a controlled manner.

The QNET case: from alert to isolation in 128 seconds

In the published case, a user opened a malicious file, likely delivered by email or browser download. The attacker then abused the legitimate Windows utility mshta.exe to retrieve a second-stage payload from external infrastructure and prepare persistence. Defender detected the suspicious execution at 09:23:20, decided on disruption at 09:25:02, and completed device isolation at 09:25:28.

After isolation, Microsoft observed neither additional payload stages nor lateral movement. The important point is not the number 128 alone. The incident demonstrates how an automated response can bridge the time during which an analyst would otherwise need to pick up the alert, assess it, and respond manually.

Why disabling a user account is not always enough

Many attack scenarios can be slowed by containing a compromised identity or revoking active sessions. Once malicious code is already running locally on an endpoint, however, the attacker can continue operating independently of that user account, steal credentials, manipulate processes, or establish further persistence. The new device isolation action therefore complements the existing measures for compromised users and identities.

This is particularly relevant for organisations without a continuously staffed SOC. Automatic disruption does not replace root-cause analysis or remediation, but it can prevent one compromised workstation from developing into a larger incident.

Requirements and current preview status

Automatic device isolation currently works only for end-user workstations that are onboarded to and managed by Microsoft Defender for Endpoint. Microsoft lists several possible licensing paths, including Microsoft 365 E5, Microsoft 365 E3 with the Defender Suite add-on, Defender for Endpoint Plan 2, and Defender for Business, alongside further qualifying licenses. Licensing alone is not sufficient: the required Defender services must be deployed and the automation settings must be configured appropriately.

Microsoft recommends the “Full – remediate threats automatically” remediation level for device groups. “Semi automation” can also allow automatic attack disruption to run without prior manual approval. Isolation is time-limited and released automatically; security operators can end it earlier when appropriate. The capability remains labelled as preview and should therefore be introduced in a controlled manner first.

Where organisations need to look closely

  • Critical systems: Devices that must not be isolated automatically need to be defined explicitly as exclusions.
  • Proxies and VPNs: Full isolation can make recovery more difficult. Microsoft recommends selective isolation in suitable environments.
  • Business-critical connections: Required processes and destinations should be defined as controlled exclusions and tested in advance.
  • Operational process: The SOC needs a clear process for reviewing, releasing, remediating, and documenting isolated devices.

What security teams should do now

  • Confirm that all relevant workstations are fully onboarded to Defender for Endpoint and up to date.
  • Review device groups, automation levels, and existing exclusions for unintended protection gaps.
  • Test selective isolation, proxy, and VPN scenarios with representative devices before using the preview broadly.
  • Extend the incident response playbook to cover approval, investigation, remediation, and reconnection of automatically isolated devices.

Official Microsoft sources

We can assess whether your Defender XDR environment is ready for automatic attack disruption and which exclusions are genuinely necessary as part of a Microsoft Security Assessmenttalk to us.

Recommended Next Step

Prepare Automatic Attack Disruption

Review onboarding, automation settings, and exclusions in your Defender XDR environment.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment