Skip to content

Commit f232acb

Browse files
authored
Merge pull request #714 from cventour/patch-1
Update respond-machine-alerts.md
2 parents 4576eba + 1428de2 commit f232acb

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

defender-endpoint/respond-machine-alerts.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -315,6 +315,9 @@ When an identity in your network might be compromised, you must prevent that ide
315315
> [!NOTE]
316316
> Blocking incoming communication with a "contained" user is supported on onboarded Microsoft Defender for Endpoint Windows 10 and 11 devices (Sense version 8740 and higher), Windows Server 2019+ devices, and Windows Servers 2012R2 and 2016 with the modern agent.
317317
318+
> [!IMPORTANT]
319+
> Once a **Contain user** action is enforced on a domain controller, it starts a GPO update on the Default Domain Controller policy. A change of a GPO starts a sync across the domain controllers in your environment. This is expected behavior, and if you monitor your environment for AD GPO changes, you may be notified of such changes. Undoing the **Contain user** action reverts the GPO changes to their previous state, which will then start another AD GPO synchronization in your environment. Learn more about [merging of security policies on domain controllers](/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj966251(v=ws.11)#merging-of-security-policies-on-domain-controllers).
320+
318321
### How to contain a user
319322

320323
Currently, containing users is only available automatically by using automatic attack disruption. When Microsoft detects a user as being compromised a "Contain User" policy is automatically set.

0 commit comments

Comments
 (0)