-
Notifications
You must be signed in to change notification settings - Fork 205
Closed
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: MediumIssues that take moderate but not substantial time to completeIssues that take moderate but not substantial time to completePriority: MediumIssues that have relevance, but aren't urgentIssues that have relevance, but aren't urgentTeam: EDR WorkflowsFormerly Defend Workflows, Onboarding and Lifecycle ManagementFormerly Defend Workflows, Onboarding and Lifecycle Managementv8.18.0
Description
Description
We are releasing our bidirectional capability with Microsoft Defender for Endpoint, which will allow users to execute host isolation / release of a MDE agent through elastic security.
This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/response-actions-config.html
Background & resources
- PRs:
- Issues/metas: https://github.com/elastic/security-team/issues/10821
- Point of contact: @caitlinbetz @ashokaditya @paul-tavares
- Test environments:
Which documentation set does this change impact?
ESS and serverless
ESS release
N/A
Serverless release
January 27, 2025
Feature differences
Feature will be the same in serverless/ESS
ESS release: 8.18
API docs impact
TBD
Prerequisites, privileges, feature flags
ESS & Serverless, Kibana privileges:
Security solution privilege: Host Isolation (ALL)
Actions and Connectors privilege:: EDR Connectors
Metadata
Metadata
Assignees
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: MediumIssues that take moderate but not substantial time to completeIssues that take moderate but not substantial time to completePriority: MediumIssues that have relevance, but aren't urgentIssues that have relevance, but aren't urgentTeam: EDR WorkflowsFormerly Defend Workflows, Onboarding and Lifecycle ManagementFormerly Defend Workflows, Onboarding and Lifecycle Managementv8.18.0