Closed
Description
Description
We are releasing our bidirectional capability with Microsoft Defender for Endpoint, which will allow users to execute host isolation / release of a MDE agent through elastic security.
This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/response-actions-config.html
Background & resources
- PRs:
- Issues/metas: https://github.com/elastic/security-team/issues/10821
- Point of contact: @caitlinbetz @ashokaditya @paul-tavares
- Test environments:
Which documentation set does this change impact?
ESS and serverless
ESS release
N/A
Serverless release
January 27, 2025
Feature differences
Feature will be the same in serverless/ESS
ESS release: 8.18
API docs impact
TBD
Prerequisites, privileges, feature flags
ESS & Serverless, Kibana privileges:
Security solution privilege: Host Isolation (ALL)
Actions and Connectors privilege:: EDR Connectors