← All integrations
Endpoint protection & containment Controls

Microsoft Defender for Endpoint

Take a device off the network straight from the incident

This connector links containment actions to Microsoft Defender for Endpoint. isidaten looks the device up by hostname, requires exactly one match and issues the isolation against it. Full isolation permits only the connection to the Defender service; selective isolation additionally keeps Outlook, Teams and Skype for Business open so the person affected stays reachable. The link is deliberately one-way: it performs interventions, it does not read detections. What Defender finds stays in Defender.

Vendor: Microsoft · learn.microsoft.com/defender-endpoint

What the connector performs
  • Isolate a device (full or selective)
  • Lift the isolation again, with no on-site visit
  • Device lookup by hostname, aborting when ambiguous
  • Connection test before first use
Your benefits

One console less when it counts

The intervention is created where the incident is documented, with a justification and a second person’s approval.

A dedicated app registration

Only what is needed is granted: Machine.Isolate and Machine.Read.All. The permission is tied to this service principal and can be revoked on its own.

Connect Microsoft Defender for Endpoint with isidaten

We show you the connector live in your own environment – non-binding and free of charge.