The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
Live response opens a cloud-based remote shell on a device so an analyst can collect forensic data, run scripts, send entities for analysis and remediate threats in real time. Start it with Initiate live response session on the device page; when finished, select Disconnect session.
Three separate toggles in Settings > Endpoints > Advanced features control live response:
| Setting | Purpose | Notes |
|---|---|---|
| Live Response | Allows sessions on devices | Required; only admins or users with Manage Portal Settings can turn it on |
| Live Response for Servers | Allows sessions on servers | Recommended; same permission to turn on |
| Live Response unsigned script execution | Allows unsigned PowerShell scripts to run | Optional and increases exposure; signature verification applies only to PowerShell scripts |
Supported platforms include Windows 10 (1909 or later, or earlier builds with specific updates), Windows 11, Windows Server 2019 and later, Windows Server 2016 and 2012 R2 with the unified agent, macOS and Linux (minimum agent versions), and Azure Local (formerly Azure Stack HCI) OS version 23H2 or later. Devices onboarded with restricted response actions don’t support live response script execution.
| Unified RBAC permission | Allows |
|---|---|
| Basic live response | Start a session, download files and perform read-only actions |
| Advanced live response | Advanced commands, including uploading files and running scripts |
| File collection | Collect or download files, including executables (the old “advanced” live response capability maps to Advanced live response plus File collection) |
Uploading a file to the library from inside a session needs Manage Security Settings; uploading from the Library management page doesn’t.
| Basic commands (examples) | Advanced commands |
|---|---|
cd, dir, cls, help, connect |
run - run a PowerShell or Bash script from the library |
processes, services, drivers, connections (Windows) |
library - list files in the library |
persistence, scheduledtasks, startupfolders, registry (Windows) |
putfile - copy a library file to the device (deleted on restart by default) |
fileinfo, findfile, getfile |
remediate - delete a file or registry entry, stop a process or service and delete its image, remove a scheduled task, delete a startup item |
jobs, fg <command ID>, status, trace |
undo - restore a remediated entity (Windows) |
analyze - verdict from incrimination engines (Windows) |
|
scan, collect, isolate, release (collect and scan on macOS and Linux; isolate and release on macOS) |
Points to remember:
run can use them. Parameters go in -parameters, without the characters ;, &, |, ! or $.remediate has a prerequisite command; -auto runs it automatically.& to getfile to run it in the background (or press Ctrl+Z while waiting), then bring it back with fg <command ID>; fg takes the ID from jobs, not a process ID.remediate can continue on the device.-output json or -output table, and redirected to a file with >. The Command log tab records every command.run get-process-by-name.ps1 -parameters "-processName Registry"
getfile "C:\windows\some_file.exe" &
remediate file c:\Users\user\Desktop\malware.exe -auto
undo file c:\Users\user\Desktop\malware.exe
These run a library script with a parameter, download a file in the background, remediate a file (running its prerequisite automatically), and restore it.
| Limit | Value |
|---|---|
| Concurrent live response sessions | 50 |
| Inactive session timeout | 30 minutes |
| Sessions per user | 5 concurrent |
| Sessions per device | 1 at a time |
| Command time limit | 10 minutes; 30 minutes for getfile, findfile and run |
getfile file size |
3 GB |
fileinfo file size |
30 GB |
| Library file size | 250 MB (5 MB default in US Government clouds) |
putfile file size |
300 MB on Windows, 10 MB on other platforms |
Common trap: Turning on Live Response and expecting sessions on servers - servers need the separate Live Response for Servers advanced feature, and unsigned PowerShell scripts need a third toggle.
Common trap: Running a script stored on the analyst’s workstation with
run- only scripts already uploaded to the live response library can be run.
Common trap: Opening a second live response session on a device another analyst is already connected to - a device can be in only one session at a time.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.