Skip to content

Commit 4a9ce03

Browse files
authored
Merge pull request #2794 from noamhadash/patch-9
Update configure-attack-disruption.md
2 parents 73222bc + 24269e5 commit 4a9ce03

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

defender-xdr/configure-attack-disruption.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,9 +52,11 @@ Review the configured automation level for your device group policies, whether a
5252

5353
1. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)) and sign in.
5454

55-
2. Go to **Settings** \> **Endpoints** \> **Device groups** under **Permissions**.
55+
2. Go to **System** \> **Settings** \> **Endpoints** \> **Device groups** under **Permissions**.
5656

57-
3. Review your device group policies. Look at the **Automation level** column. We recommend using **Full - remediate threats automatically**. You might need to create or edit your device groups to get the level of automation you want. To exclude a device group from automated containment, set its automation level to **no automated response**. Note that this is not highly recommended and should only be done for a limited number of devices.
57+
3. Review your device group policies and look at the **Remediation level** column. We recommend using **Full - remediate threats automatically**.
58+
59+
You can also create or edit your device groups to set the appropriate remediation level for each group. Selecting the **Semi automation** level allows triggering of automatic attack disruption without the need for manual approval. To exclude a device group from automated containment, you can set its automation level to **no automated response**. Note that this setting is not highly recommended and should only be done for a limited number of devices.
5860

5961
#### Device discovery configuration
6062

0 commit comments

Comments
 (0)