Microsoft Defender For Endpoint - Unisolate Endpoint
This playbook accepts an endpoint ID, IP, or host name and unisolates it using the Microsoft Defender For Endpoint integration.
- Pack
- MicrosoftDefenderAdvancedThreatProtection
- Tasks
- 23
Inputs
- Device_id — The device ID to isolate. For more information about the device, you can use the following commands: !microsoft-atp-get-machine-details !microsoft-atp-get-machines
- Hostname — The device host name you want to isolate.
- Device_IP — The device IP you want to isolate.
Outputs
- MicrosoftATP.MachineAction.ID — The machine action ID.
- MicrosoftATP.NonUnisolateList — The machine IDs that will not be released from isolation.
- MicrosoftATP.UnisolateList — The machine IDs that were released from isolation.
- MicrosoftATP.IncorrectIDs — Incorrect device IDs entered.
- MicrosoftATP.IncorrectHostnames — Incorrect host names entered.
- MicrosoftATP.IncorrectIPs — Incorrect device IPs entered.
Commands used
- endpoint
- microsoft-atp-unisolate-machine