Skip to content

Commit 1428de2

Browse files
authored
Update respond-machine-alerts.md
updated added note and link under contain user
1 parent 1bdd100 commit 1428de2

File tree

1 file changed

+1
-6
lines changed

1 file changed

+1
-6
lines changed

defender-endpoint/respond-machine-alerts.md

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -316,12 +316,7 @@ When an identity in your network might be compromised, you must prevent that ide
316316
> Blocking incoming communication with a "contained" user is supported on onboarded Microsoft Defender for Endpoint Windows 10 and 11 devices (Sense version 8740 and higher), Windows Server 2019+ devices, and Windows Servers 2012R2 and 2016 with the modern agent.
317317
318318
> [!IMPORTANT]
319-
>Once a Contain User action is enforced on a Domain Controller, it will trigger a GPO update on the Default Domain Controller policy. A change of a GPO will trigger a sync across the Domain Controllers in your environment. The above is expected behavior, and if you monitor your environment for AD GPO changes, you may be notified of such changes. Undoing the Contain User action will also revert the GPO changes to their previous state which will once more trigger AD GPO synchronization in your environment.
320-
321-
More information on merging of Security Policies can be found at
322-
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj966251(v=ws.11)#merging-of-security-policies-on-domain-controllers
323-
324-
319+
> Once a **Contain user** action is enforced on a domain controller, it starts a GPO update on the Default Domain Controller policy. A change of a GPO starts a sync across the domain controllers in your environment. This is expected behavior, and if you monitor your environment for AD GPO changes, you may be notified of such changes. Undoing the **Contain user** action reverts the GPO changes to their previous state, which will then start another AD GPO synchronization in your environment. Learn more about [merging of security policies on domain controllers](/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj966251(v=ws.11)#merging-of-security-policies-on-domain-controllers).
325320
326321
### How to contain a user
327322

0 commit comments

Comments
 (0)