Microsoft is putting containment inside Defender for Endpoint, and that same automation can become a disruption point if it is left too loose. The promise is fast isolation of a suspected device; the risk is that response logic itself can be abused to knock administrators off their accounts and slow incident handling.
The feature is in preview as part of automatic attack disruption. A compromised endpoint is cut off from the network but still monitored by Defender, and Microsoft says it applies to onboarded end-user workstations managed by Defender for Endpoint.
SANS is warning that, in certain conditions, attackers could use the new function to disable user accounts used by administrators. The practical shift is that quarantine is no longer just about trapping an endpoint; it also becomes part of the attack surface that can strand defenders when they need control most.
Microsoft previews automatic device isolation in Defender for Endpoint
The new capability will be added to the automatic attack disruption tool, however, new research warns that the tool has to be tuned to avoid it becoming an attack vector.
Microsoft Defender can now automatically isolate hacked endpoints
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network.