Home › Glossary › Automatic attack disruption

Automatic attack disruption

A Microsoft Defender XDR feature that links signals into a high-confidence incident and, while ransomware, business email compromise or a similar attack is still in progress, contains the affected accounts and devices on its own. Security staff can reverse these actions.

Read more: Microsoft Learn

In the Ultra Transcenders books

SC-900SC-200

Each book explains Automatic attack disruption in context, with comparison tables and the common traps.

Terms in this definition

Related terms

See Automatic attack disruption in the full glossary