I enabled Microsoft Defender Attack Disruption and its automatic account-disablement capability. This was configuration of a native response feature. The KQL used to identify accounts Defender had disabled was an investigation query, separate from the product’s containment action.
Viewed
UK Water Utility
Native automated account containment
Automate endpoint investigation and response
Return to the full story ←