Defender’s New Quarantine Can Also Jam Response

Microsoft is putting containment inside Defender for Endpoint, and that same automation can become a disruption point if it is left too loose. The promise is fast isolation of a suspected device; the risk is that response logic itself can be abused to knock administrators off their accounts and slow incident handling. The feature is in preview as part of automatic attack disruption. A compromised endpoint is cut off from the network but still monitored by Defender, and Microsoft says it applies to onboarded end-user workstations managed by Defender for Endpoint. SANS is warning that, in certain conditions, attackers could use the new function to disable user accounts used by administrators. The practical shift is that quarantine is no longer just about trapping an endpoint; it also becomes part of the attack surface that can strand defenders when they need control most.

Part of the PlainSec briefing for 2026-05-27

Sources