Skip to main content
Available actions depend on the entity type and your licensed integrations.

Device Actions

ActionDescriptionImpact
Isolate DeviceDisconnects device from network, maintains management connectivityHigh
Unisolate DeviceRestores network connectivityMedium
Full ScanComprehensive antivirus/antimalware scanLow
Quick ScanFast scan of common threat locationsLow
Offboard DeviceRemoves device from Defender for EndpointHigh

User Actions

ActionDescriptionImpact
Disable AccountDisables Entra ID accountHigh
Enable AccountRe-enables disabled accountMedium
Reset PasswordForces password reset on next sign-inHigh
Revoke SessionsInvalidates all active auth tokensMedium
Block Sign-inBlocks user from authenticatingHigh

Network Actions

ActionDescriptionImpact
Block IPBlocks IP addressMedium
Block URLBlocks URL/domainMedium

File Actions

ActionDescriptionImpact
Quarantine FileIsolates file to prevent executionMedium

Email Actions

ActionDescriptionImpact
Soft Delete EmailRemoves email from mailboxes (recoverable)Medium
High-impact actions may require approval workflows depending on your configuration.