One console less when it counts
The intervention is created where the incident is documented, with a justification and a second person’s approval.
Take a device off the network straight from the incident
This connector links containment actions to Microsoft Defender for Endpoint. isidaten looks the device up by hostname, requires exactly one match and issues the isolation against it. Full isolation permits only the connection to the Defender service; selective isolation additionally keeps Outlook, Teams and Skype for Business open so the person affected stays reachable. The link is deliberately one-way: it performs interventions, it does not read detections. What Defender finds stays in Defender.
Vendor: Microsoft · learn.microsoft.com/defender-endpoint
The intervention is created where the incident is documented, with a justification and a second person’s approval.
Only what is needed is granted: Machine.Isolate and Machine.Read.All. The permission is tied to this service principal and can be revoked on its own.
We show you the connector live in your own environment – non-binding and free of charge.