Skip to content

Commit 2f8effb

Browse files
authored
Merge pull request #1301 from MicrosoftDocs/diannegali-updatecontaindevice
updated contain device
2 parents 05a8ffe + 815ada9 commit 2f8effb

File tree

1 file changed

+7
-2
lines changed

1 file changed

+7
-2
lines changed

defender-endpoint/respond-machine-alerts.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.service: defender-endpoint
55
ms.author: diannegali
66
author: diannegali
77
ms.localizationpriority: medium
8-
ms.date: 12/15/2023
8+
ms.date: 09/09/2024
99
manager: deniseb
1010
audience: ITPro
1111
ms.collection:
@@ -266,11 +266,13 @@ When a device is being isolated, the following notification is displayed to info
266266
267267
## Contain devices from the network
268268

269-
When you have identified an unmanaged device that is compromised or potentially compromised, you might want to contain that device from the network. When you contain a device any Microsoft Defender for Endpoint onboarded device will block incoming and outgoing communication with that device. This action can help prevent neighboring devices from becoming compromised while the security operations analyst locates, identifies, and remediates the threat on the compromised device.
269+
When you have identified an unmanaged device that is compromised or potentially compromised, you might want to contain that device from the network to prevent the potential attack from moving laterally across the network. When you contain a device any Microsoft Defender for Endpoint onboarded device will block incoming and outgoing communication with that device. This action can help prevent neighboring devices from becoming compromised while the security operations analyst locates, identifies, and remediates the threat on the compromised device.
270270

271271
> [!NOTE]
272272
> Blocking incoming and outgoing communication with a 'contained' device is supported on onboarded Microsoft Defender for Endpoint Windows 10 and Windows Server 2019+ devices.
273273
274+
Once devices are contained, we recommend investigating and remediating the threat on the contained devices as soon as possible. After remediation, you should remove the devices from containment.
275+
274276
### How to contain a device
275277

276278
1. Go to the **Device inventory** page and select the device to contain.
@@ -283,6 +285,9 @@ When you have identified an unmanaged device that is compromised or potentially
283285

284286
:::image type="content" alt-text="Screenshot of the contain device menu item." source="/defender/media/defender-endpoint/contain_device_popup.png" lightbox="/defender/media/defender-endpoint/contain_device_popup.png":::
285287

288+
> [!IMPORTANT]
289+
> Containing a large number of devices might cause performance issues on Defender for Endpoint-onboarded devices. To prevent any issues, Microsoft recommends containing up to 100 devices at any given time.
290+
286291
### Contain a device from the device page
287292

288293
A device can also be contained from the device page by selecting **Contain device** from the action bar:

0 commit comments

Comments
 (0)