Event details
The next evolution of automatic attack disruption
Our season finale is going in-depth on an innovative, industry-first capability that marks a significant step forward for defenders gaining gro...
Trevor_Rusher
Updated Dec 27, 2024
HeikeRitter
Microsoft
Oct 12, 2023Hi all, welcome! Please feel free to ask your questions here 🙂
- sassdaweOct 12, 2023MCTHow is this new capability coming into play at a cloud-only environment where there is no Active Directory, no servers, nothing, but only Entra ID joined devices?
- HeikeRitterOct 12, 2023
Microsoft
Hi David! This capability is not depended on Active Directory, and it will still provide protection also for Entra ID joined devices onboarded to Microsoft Defender for Endpoint. "Contain user" also knows how to contain compromised Entra ID user accounts that are attempting to move laterally in the network, including but not limited to, stopping and terminating Remote Desktop sessions.
- Adrian AmosOct 12, 2023Copper ContributorHaving "Attack Disruption" events in KQL hunting queries is a great start, but it would be awesome to have these events published to the "Action Center", as well.
- HeikeRitterOct 12, 2023
Microsoft
Thank you for the suggestion. Appreciate your feedback!
- avanderwaltOct 12, 2023Copper ContributorHmmm - just seeing "Video Unavailable". Anything I should do differently or is there a technical issue?
- HeikeRitterOct 12, 2023
Microsoft
Hmm... no problems here - can you see it here? https://www.youtube.com/watch?v=cx3Y9Yg0aN4- avanderwaltOct 12, 2023Copper ContributorNo - I'm afraid not 😞 I guess I'll catch up on the recording.