Isolate a Microsoft Defender endpoint machine
Use “Isolate a Microsoft Defender endpoint machine” in Recued. It runs the Microsoft Defender for Endpoint machine isolation workflow for one machine with approval before changes are made.
How it works
Inspect the data fetches, transforms, gates, and output this recipe runs.
Process (9 steps)
machine_id
trim
Trim whitespace from setting machine id
comment
trim
Trim whitespace from setting comment
machine_before
?
alerts_raw
?
isolate
?
alerts
default
Apply default
alert_count
count
Count items in alerts
card
to_summary
Format results as a summary card
alerts_table
to_table
Format results as a data table
Settings
Configurable at install. Defaults shown — change them anytime in Recued.
comment
setting
=
Isolate machine for security investigation.
machine id
setting
=
isolation type
setting
=
Selective
microsoft defender
setting
=
Trust & control
What installing this recipe would let it do. Recued grants these permissions at install — review them there before approving.