Skip to content

Commit 8aa1b1a

Browse files
authored
Update configure-attack-disruption.md
stating explicitly that "semi" state will still allow disruption
1 parent fac564a commit 8aa1b1a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-xdr/configure-attack-disruption.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ Review the configured automation level for your device group policies, whether a
5454

5555
2. Go to **Settings** \> **Endpoints** \> **Device groups** under **Permissions**.
5656

57-
3. Review your device group policies. Look at the **Automation level** column. We recommend using **Full - remediate threats automatically**. You might need to create or edit your device groups to get the level of automation you want. To exclude a device group from automated containment, set its automation level to **no automated response**. Note that this is not highly recommended and should only be done for a limited number of devices.
57+
3. Review your device group policies. Look at the **Automation level** column. We recommend using **Full - remediate threats automatically**. You might need to create or edit your device groups to get the level of automation you want. To exclude a device group from automated containment, set its automation level to **no automated response** (Semi autoamtion level will allow triggering of automatic attack disruption with no need for manual approval). Note that this is not highly recommended and should only be done for a limited number of devices.
5858

5959
#### Device discovery configuration
6060

0 commit comments

Comments
 (0)