Event details
Learn more about attack disruption—Microsoft Defender’s built‑in, AI-powered capability that stops in‑progress attacks at machine speed by analyzing attacker intent, identifying compromised assets, and containing threats before they spread. Bring your questions and hear directly from product experts on real‑world scenarios and best practices.
What is an AMA?
An 'Ask Microsoft Anything' (AMA) session is an opportunity for you to engage directly with Microsoft employees! This AMA will consist of a short presentation followed by taking questions on-camera from the comment section down below! Ask your questions/give your feedback and we will have our awesome Microsoft Subject Matter Experts engaging and responding directly in the video feed. We know this timeslot might not work for everyone, so feel free to ask your questions at any time leading up to the event and the experts will do their best to answer during the live hour. This page will stay up evergreen so come back and use it as a resource anytime. We hope you enjoy!
25 Comments
- TrevorRusher
Community Manager
Great questions everyone, keep them coming! The session will be roughly 20 more minutes.
- PuravsPointTin Contributor
Great that you support user level attack disruption in 3rd party like Okta, AWS, wasn't aware of that. Are there plans for similar device level attack disruption in 3rd party EDR's ?
- MeatBear11Copper Contributor
I thought I heard that set up only includes having Defender installed. Can you expand on the installation and setup steps to have the protection and to monitor systems? I also thought I read something about how Sentinel is moving into Defender. How does this impact deployment. Is there a difference in managing this in Intune or Defender? Is it one or the other? Can you show this?
- MeatBear11Copper Contributor
Can you comment on Azure Arc data being collected as well?
- PuravsPointTin Contributor
Can you explain more about the application used to perform attack disruption? Think it's called Radius Aad Syncer or Defender for Identity. It's slightly confusing because companies that don't have MDI deployed will still see an app named as MDI. What is the right workflow here? Attack disruption attempts to disable a user but due to no MDI, it fails. However Attack disruption is able to force user out of sessions and also mark them as compromised in entra id. It's a bit of a confusing experience.
Hi everyone,
the new feature has a separate license or exists in P2 plan ?
What are the differences from previous actions that MDfE gave us in the past ? More proactive actions maybe ? more confidence about the probability of true positive attack ?
Does a security admin can audit - view changes made automatically by the service ? In order to fine tune them, or even disable-delete them after the containment - remediation of the attack ?
Thanks,
Panos- PuravsPointTin Contributor
You can see/audit what actions attack disruption took in a particular Defender XDR Incident within Activities and apply a filer of "Performed by: XDR Attack Disruption" or Action Center with similar filters. Hope it helps.
- TrevorRusher
Community Manager
Hello everyone! The event will begin soon. Please remember to ask questions down here in this comment section for the experts to see. I hope everyone learns something new today! Thanks!
- my_8603Occasional Reader
Good luck
- Abdullah6642Copper Contributor
Very good for learning
- tygabillionzTin Contributor
Fantastic.. I learnt something new today about AMA.. thank you.
- TrevorRusher
Community Manager
Very excited to share this AMA with you all in a couple weeks! As a reminder, please keep the questions ON-TOPIC. You can post them here in this comment section and the team will try their best to answer during the live event. Thank you!
- hamidzehzad779Copper Contributor
Hi I'm hamid Behzad