Explore Our Microsoft Cloud Security Training →
Introduction:
Isolating Compromised Devices:
To isolate a device, navigate to the MDE portal and initiate device actions. This will sever network connections, limiting the attacker’s scope.
Running Live Response Sessions:
Once isolated, start a live response session for forensic investigation. Gathering evidence is crucial to understanding the attack and its origin.
Collecting Investigation Packages:
During the live response session, collect an investigation package from the isolated device for further analysis.
Advanced Hunting:
Utilize Advanced Hunting to trace attacker activity across your environment. Query patterns of behavior to identify potential threats and their source.
Remediation:
After identifying the threat, remediate the affected device to prevent future intrusions.
Releasing Devices from Isolation:
Once remediation is complete, release the device from isolation to restore full network access.
Explore Our Microsoft Cloud Security Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
