Recued
Menu
← Back to recipes

Isolate a Microsoft Defender endpoint machine

by recued-core v1 8 views

Use “Isolate a Microsoft Defender endpoint machine” in Recued. It runs the Microsoft Defender for Endpoint machine isolation workflow for one machine with approval before changes are made.

How it works 9 steps

Inspect the data fetches, transforms, gates, and output this recipe runs.

Process (9 steps)
machine_id trim
Trim whitespace from setting machine id
comment trim
Trim whitespace from setting comment
machine_before ?
alerts_raw ?
isolate ?
alerts default
Apply default
alert_count count
Count items in alerts
card to_summary
Format results as a summary card
alerts_table to_table
Format results as a data table
Settings 4 configurable

Configurable at install. Defaults shown — change them anytime in Recued.

comment setting = Isolate machine for security investigation.
machine id setting =
isolation type setting = Selective
microsoft defender setting =

Trust & control

What installing this recipe would let it do. Recued grants these permissions at install — review them there before approving.

Permissions it requires

Read your Microsoft-defender connection
Declared by the recipe — Recued grants these at install, where you review them before approving.

About

Tags

microsoft-defender-endpoint microsoft-defender-endpointdefender-for-endpointendpoint-securitymachinesisolateincident-responseapprovalpack:microsoft-defender-endpoint

Details

9 steps 4 configurable settings recipe_id: isolate-machine-microsoft-defender-endpoint