Event details

Learn more about attack disruption—Microsoft Defender’s built‑in, AI-powered capability that stops in‑progress attacks at machine speed by analyzing attacker intent, identifying compromised assets, and containing threats before they spread. Bring your questions and hear directly from product experts on real‑world scenarios and best practices.

 

What is an AMA?

An 'Ask Microsoft Anything' (AMA) session is an opportunity for you to engage directly with Microsoft employees! This AMA will consist of a short presentation followed by taking questions on-camera from the comment section down below! Ask your questions/give your feedback and we will have our awesome Microsoft Subject Matter Experts engaging and responding directly in the video feed. We know this timeslot might not work for everyone, so feel free to ask your questions at any time leading up to the event and the experts will do their best to answer during the live hour. This page will stay up evergreen so come back and use it as a resource anytime. We hope you enjoy!

 

Trevor_Rusher
Updated Jul 14, 2026

25 Comments

  • TrevorRusher's avatar
    TrevorRusher
    Icon for Community Manager rankCommunity Manager

    Great questions everyone, keep them coming! The session will be roughly 20 more minutes.

  • Great that you support user level attack disruption in 3rd party like Okta, AWS, wasn't aware of that. Are there plans for similar device level attack disruption in 3rd party EDR's ?

  • MeatBear11's avatar
    MeatBear11
    Copper Contributor

    I thought I heard that set up only includes having Defender installed. Can you expand on the installation and setup steps to have the protection and to monitor systems? I also thought I read something about how Sentinel is moving into Defender. How does this impact deployment. Is there a difference in managing this in Intune or Defender? Is it one or the other? Can you show this?

     

    • MeatBear11's avatar
      MeatBear11
      Copper Contributor

      Can you comment on Azure Arc data being collected as well?

       

  • Can you explain more about the application used to perform attack disruption? Think it's called Radius Aad Syncer or Defender for Identity. It's slightly confusing because companies that don't have MDI deployed will still see an app named as MDI. What is the right workflow here? Attack disruption attempts to disable a user but due to no MDI, it fails. However Attack disruption is able to force user out of sessions and also mark them as compromised in entra id. It's a bit of a confusing experience.

  • Hi everyone, 
    the new feature has a separate license or exists in P2 plan ?
    What are the differences from previous actions that MDfE gave us in the past ? More proactive actions maybe ? more confidence about the probability of true positive attack ?

    Does a security admin can audit - view changes made automatically by the service ? In order to fine tune them, or even disable-delete them after the containment - remediation of the attack ?

    Thanks,
    Panos

    • PuravsPoint's avatar
      PuravsPoint
      Tin Contributor

      You can see/audit what actions attack disruption took in a particular Defender XDR Incident within  Activities and apply a filer of "Performed by: XDR Attack Disruption" or Action Center with similar filters. Hope it helps.

  • TrevorRusher's avatar
    TrevorRusher
    Icon for Community Manager rankCommunity Manager

    Hello everyone! The event will begin soon. Please remember to ask questions down here in this comment section for the experts to see. I hope everyone learns something new today! Thanks!

  • TrevorRusher's avatar
    TrevorRusher
    Icon for Community Manager rankCommunity Manager

    Very excited to share this AMA with you all in a couple weeks! As a reminder, please keep the questions ON-TOPIC. You can post them here in this comment section and the team will try their best to answer during the live event. Thank you!