Skip to main content
Solved

On Demand Machine Isolation for Defender

  • July 24, 2025
  • 1 reply
  • 46 views

jetheridge
Forum|alt.badge.img+1

Hey all, I’ve noticed that the Microsoft Defender ATP SOAR Integration has “Create Isolate Machine Task” and accompanying unisolate machine task actions. However, these find the host directly from the alert. I want to be able to have isolate and unisolate actions that can take in a hostname/hostid as an input so that they can be ran ad-hoc. Any ideas?

Best answer by _eo

You would need to add the hostname or ip address as an entity to a case (new or existing) and then run the action ad-hoc. The integration actions are really meant to be run against cases and their associated entities. Another option could be to clone the actions and customize as needed. You would likely need to run them from the IDE or as an ad-hoc job.

1 reply

_eo
Forum|alt.badge.img+4
  • Bronze 2
  • Answer
  • July 25, 2025

You would need to add the hostname or ip address as an entity to a case (new or existing) and then run the action ad-hoc. The integration actions are really meant to be run against cases and their associated entities. Another option could be to clone the actions and customize as needed. You would likely need to run them from the IDE or as an ad-hoc job.