185 questions
- You can leverage Graph API and Power Automate to achieve auto - Isolation:
- Acquire these permissions On your application page, select API Permissions > Add permission > APIs my organization uses > type WindowsDefenderATP and select on WindowsDefenderATP.
- Graph Query - https://api.securitycenter.microsoft.com/api/alerts
- Power Automate - https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-microsoft-flow?view=o365-worldwide#isolate-the-device-if-the-alerts-severity-is-high