Skip to main content

MicrosoftAtpUnisolateMachine

This Script is part of the Microsoft Defender for Endpoint Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.1.0 and later.

A polling wrapper script; isolates a machine from accessing external networks.

Script Data#


NameDescription
Script Typepython3
TagsUtilities
Cortex XSOAR Version6.1.0

Inputs#


Argument NameDescription
machine_idA comma-separated list of machine IDs to be used to stop the isolation. For example: 0a3250e0693a109f1affc9217be9459028aa8426,0a3250e0693a109f1affc9217be9459028aa8424.
commentComment to associate with the action.
ran_once_flagFlag for the rate limit retry.

Outputs#


PathDescriptionType
MicrosoftATP.Machine.Isolation.RequestorMachine un-isolation requestor.string
MicrosoftATP.Machine.Isolation.RequestorCommentMachine un-isolation requestor comment.string
MicrosoftATP.Machine.IDMachine ID.Unknown