Recued
Menu
← Back to recipes

Release a Microsoft Defender endpoint machine from isolation

by recued-core v1 10 views

Use “Release a Microsoft Defender endpoint machine from isolation” in Recued. It runs the Microsoft Defender for Endpoint release-from-isolation workflow for one machine with approval before changes are made.

How it works 10 steps

Inspect the data fetches, transforms, gates, and output this recipe runs.

Process (10 steps)
machine_id trim
Trim whitespace from setting machine id
comment trim
Trim whitespace from setting comment
machine_action_filter template
Generate text from a template
machine_before ?
actions_raw ?
release ?
actions default
Apply default
action_count count
Count items in actions
card to_summary
Format results as a summary card
actions_table to_table
Format results as a data table
Settings 3 configurable

Configurable at install. Defaults shown — change them anytime in Recued.

comment setting = Release machine from isolation after validation.
machine id setting =
microsoft defender setting =

Trust & control

What installing this recipe would let it do. Recued grants these permissions at install — review them there before approving.

Permissions it requires

Read your Microsoft-defender connection
Declared by the recipe — Recued grants these at install, where you review them before approving.

About

Tags

microsoft-defender-endpoint microsoft-defender-endpointdefender-for-endpointendpoint-securitymachinesunisolateincident-responseapprovalpack:microsoft-defender-endpoint

Details

10 steps 3 configurable settings recipe_id: release-machine-isolation-microsoft-defender-endpoint