Ransomware spreads through corporate networks in minutes. One compromised workstation becomes the foothold, and within a matter of minutes, the damage cascades across the organization. That critical window between detection and containment has long been the weakest link in enterprise security operations. Microsoft is now testing a capability designed to close that gap entirely: automatic device isolation in Microsoft Defender for Endpoint, triggered without human intervention the moment a compromise is detected with high confidence.
Microsoft Tests Automatic Device Isolation in Defender for Endpoint
Microsoft has introduced a new preview feature within the automatic attack disruption framework of Defender for Endpoint. The capability automatically isolates endpoints suspected of compromise from the corporate network. Previously, device isolation was a manual action that required a security administrator to assess the alert, confirm the compromise, and execute the containment measure. The new preview makes isolation the default response when Defender detects an intrusion with sufficient certainty.
The mechanism is straightforward. When Defender for Endpoint identifies a compromised endpoint with confidence levels exceeding 99 percent, the device is automatically severed from the network. Importantly, the isolated device retains communication with the Defender for Endpoint cloud service, enabling the security team to continue collecting telemetry and conducting remote investigation while the device remains contained.
Automatic isolation reduces the risk of further attack expansion, restricts lateral movement, and prevents data exfiltration or ransomware propagation, Microsoft stated in its documentation for the feature.
The feature is part of a broader framework Microsoft calls automatic attack disruption, which has been expanding in scope over the past several years with capabilities ranging from manual containment to automatic user account disabling and IP address blocking.
Closing the Critical Gap Between Detection and Response
The problem automatic isolation aims to solve is well understood by anyone who has worked in security operations. In a typical incident, the time between an alert firing and a human operator executing containment can stretch from tens of minutes to several hours. The SOC must validate the alert, assess the blast radius, check for false positives, coordinate with stakeholders, and then finally pull the trigger on containment. In the context of modern ransomware and credential theft attacks, those minutes are decisive.
Attackers who have gained initial access to a single workstation move laterally within minutes. They dump credentials, enumerate the environment, and deploy ransomware or exfiltrate data before the security team has finished its initial triage. The attacker’s speed is already machine-driven. Human response speed, even in well-staffed SOCs, is not.
Automatic device isolation inserts a machine-speed decision into that gap. By relying on Defender’s detection engine, which combines machine learning, cross-workload correlation analysis, and expert incident classification, the feature can execute containment in seconds rather than minutes or hours. Microsoft states that the confidence threshold for triggering automatic isolation is maintained above 99 percent, a level designed to minimize business disruption from false positives while still catching genuine compromises early.
How does automatic device isolation in Microsoft Defender work? When Defender for Endpoint detects a compromise on a workstation with confidence exceeding 99 percent, the device is automatically disconnected from the corporate network while maintaining communication with the Defender service. Security teams can continue to receive telemetry and investigate the incident remotely, and administrators can release the isolation at any time.
Scope and Administrative Controls: Workstations Only, with Full Oversight
The current preview comes with important limitations. Automatic device isolation applies exclusively to workstations that are onboarded to Defender for Endpoint. Servers are not included, and unmanaged or non-onboarded devices fall outside the scope. This means that if an attacker compromises a file server or a domain controller, the automatic isolation feature alone will not contain the threat. Microsoft has focused the capability on endpoints where the risk of lateral movement from a compromised user device is highest.
Administrators retain full control over the isolation action. Although the trigger is automatic, the release of isolation is always manual and can be performed at any time by the security team. Organizations can also configure exception rules to exclude specific critical workstations from automatic isolation, ensuring that business-essential endpoints are not inadvertently disrupted. The isolation action is time-limited and targets only the device directly involved in the incident.
To enable the feature once it reaches general availability, organizations will need to set the automation level for the relevant device group to full auto-remediation within the Microsoft Defender XDR portal. This granular control allows enterprises to test the capability on non-critical device groups before rolling it out broadly.
Five Years of Incremental Expansion in Automatic Attack Disruption
Microsoft’s journey toward automatic device isolation has been gradual and methodical. The company has been expanding the automatic attack disruption framework step by step since 2022.
In June 2022, Microsoft introduced manual containment for unmanaged Windows devices, giving administrators the ability to block communication with devices that were not onboarded to Defender. This was a reactive capability, but it laid the groundwork for automation. In January 2023, Linux device isolation entered preview, extending containment support to Linux endpoints. By October 2023, Linux and macOS device isolation reached general availability, and the same month, Microsoft added automatic disabling of compromised user accounts to the framework.
The next major step came in April 2025 with the Contain IP preview, which automatically blocks traffic to and from IP addresses associated with unmanaged or undetected endpoints, closing a lateral movement vector that manual isolation could not address. Now, in May 2026, automatic device isolation for compromised workstations has entered preview, representing the most significant automation milestone in the framework’s evolution.
Device isolation, user account disabling, and IP address containment now cover three distinct layers of attack disruption: the device layer, the identity layer, and the network layer. The new automatic isolation fills a critical gap in the device layer. Without it, an attacker could still operate from a compromised workstation even after their account was disabled or their IP address was blocked, because the device itself remained connected to the network.
Implications for Enterprise Security Operations
The introduction of automatic device isolation carries significant implications for how organizations structure their security operations. For enterprises that maintain a 24-hour security operations center, the feature reduces the pressure on tier-one and tier-two analysts to perform manual containment under time constraints. For smaller organizations that lack round-the-clock SOC coverage, the benefit is even more pronounced: automatic isolation can contain compromises that occur overnight or during weekends, when no security staff is available to respond.
However, the feature also introduces a new class of risk. An automatic isolation triggered by a false positive can take a critical workstation offline, potentially disrupting business operations. Microsoft’s stated confidence threshold of over 99 percent is intended to minimize this risk, but in an environment with thousands of endpoints, even a sub-one-percent false positive rate can result in multiple unnecessary isolations over the course of a year. Organizations with complex application dependencies or legacy systems are particularly vulnerable to this kind of disruption.
Security teams should treat the preview period as an opportunity to design and test exception rules carefully. Identifying which workstations can safely be included in automatic isolation, and which require manual review before containment, is essential preparation. Device groups, automation levels, and exclusion lists should be configured and validated before the feature reaches general availability.
The broader trend is clear. Attackers operate at machine speed, and the security industry has reached the limit of what human-mediated response can achieve. The most effective defense against fast-moving threats is equally fast automated containment. Microsoft’s automatic device isolation is another step in that direction, shifting the role of the security analyst from reactive containment to proactive investigation, remediation, and recovery.
The preview is available now to organizations with appropriate Defender for Endpoint licenses. Security administrators can review and configure automatic attack disruption settings, including the new device isolation capability, through the Microsoft Defender XDR portal. As with any preview feature, testing in a controlled environment before broad deployment is strongly recommended. The window between detection and containment has always been the attacker’s best opportunity. Automatic device isolation aims to make that window disappear entirely.