Skip to content

[Request] MS Defender for Endpoint, third party response integration #6303

Closed
@caitlinbetz

Description

@caitlinbetz

Description

We are releasing our bidirectional capability with Microsoft Defender for Endpoint, which will allow users to execute host isolation / release of a MDE agent through elastic security.

This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/response-actions-config.html

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

N/A

Serverless release

January 27, 2025

Feature differences

Feature will be the same in serverless/ESS

ESS release: 8.18

API docs impact

TBD

Prerequisites, privileges, feature flags

ESS & Serverless, Kibana privileges:

Security solution privilege: Host Isolation (ALL)

Actions and Connectors privilege:: EDR Connectors

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityEffort: MediumIssues that take moderate but not substantial time to completePriority: MediumIssues that have relevance, but aren't urgentTeam: EDR WorkflowsFormerly Defend Workflows, Onboarding and Lifecycle Managementv8.18.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions