Event details
Learn more about attack disruption—Microsoft Defender’s built‑in, AI-powered capability that stops in‑progress attacks at machine speed by analyzing attacker intent, identifying compromised assets, ...
Trevor_Rusher
Updated Jul 14, 2026
PanosGR191
Jul 14, 2026MCT
Hi everyone,
the new feature has a separate license or exists in P2 plan ?
What are the differences from previous actions that MDfE gave us in the past ? More proactive actions maybe ? more confidence about the probability of true positive attack ?
Does a security admin can audit - view changes made automatically by the service ? In order to fine tune them, or even disable-delete them after the containment - remediation of the attack ?
Thanks,
Panos
PuravsPoint
Jul 14, 2026Tin Contributor
You can see/audit what actions attack disruption took in a particular Defender XDR Incident within Activities and apply a filer of "Performed by: XDR Attack Disruption" or Action Center with similar filters. Hope it helps.