FREE STUDY NOTES · SC-200

Defender for Endpoint live response: settings, permissions, commands and limits

The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Live response opens a cloud-based remote shell on a device so an analyst can collect forensic data, run scripts, send entities for analysis and remediate threats in real time. Start it with Initiate live response session on the device page; when finished, select Disconnect session.

Prerequisites

Three separate toggles in Settings > Endpoints > Advanced features control live response:

Setting Purpose Notes
Live Response Allows sessions on devices Required; only admins or users with Manage Portal Settings can turn it on
Live Response for Servers Allows sessions on servers Recommended; same permission to turn on
Live Response unsigned script execution Allows unsigned PowerShell scripts to run Optional and increases exposure; signature verification applies only to PowerShell scripts

Supported platforms include Windows 10 (1909 or later, or earlier builds with specific updates), Windows 11, Windows Server 2019 and later, Windows Server 2016 and 2012 R2 with the unified agent, macOS and Linux (minimum agent versions), and Azure Local (formerly Azure Stack HCI) OS version 23H2 or later. Devices onboarded with restricted response actions don’t support live response script execution.

Permissions: basic versus advanced

Unified RBAC permission Allows
Basic live response Start a session, download files and perform read-only actions
Advanced live response Advanced commands, including uploading files and running scripts
File collection Collect or download files, including executables (the old “advanced” live response capability maps to Advanced live response plus File collection)

Uploading a file to the library from inside a session needs Manage Security Settings; uploading from the Library management page doesn’t.

Commands

Basic commands (examples) Advanced commands
cd, dir, cls, help, connect run - run a PowerShell or Bash script from the library
processes, services, drivers, connections (Windows) library - list files in the library
persistence, scheduledtasks, startupfolders, registry (Windows) putfile - copy a library file to the device (deleted on restart by default)
fileinfo, findfile, getfile remediate - delete a file or registry entry, stop a process or service and delete its image, remove a scheduled task, delete a startup item
jobs, fg <command ID>, status, trace undo - restore a remediated entity (Windows)
analyze - verdict from incrimination engines (Windows)
scan, collect, isolate, release (collect and scan on macOS and Linux; isolate and release on macOS)

Points to remember:

run get-process-by-name.ps1 -parameters "-processName Registry"
getfile "C:\windows\some_file.exe" &
remediate file c:\Users\user\Desktop\malware.exe -auto
undo file c:\Users\user\Desktop\malware.exe

These run a library script with a parameter, download a file in the background, remediate a file (running its prerequisite automatically), and restore it.

Limits

Limit Value
Concurrent live response sessions 50
Inactive session timeout 30 minutes
Sessions per user 5 concurrent
Sessions per device 1 at a time
Command time limit 10 minutes; 30 minutes for getfile, findfile and run
getfile file size 3 GB
fileinfo file size 30 GB
Library file size 250 MB (5 MB default in US Government clouds)
putfile file size 300 MB on Windows, 10 MB on other platforms

Common trap: Turning on Live Response and expecting sessions on servers - servers need the separate Live Response for Servers advanced feature, and unsigned PowerShell scripts need a third toggle.

Common trap: Running a script stored on the analyst’s workstation with run - only scripts already uploaded to the live response library can be run.

Common trap: Opening a second live response session on a device another analyst is already connected to - a device can be in only one session at a time.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes