Automatic attack disruption — AI-directed identity containment
Microsoft Defender XDR correlates cross-workload security signals using machine-learning outputs, specialised models and detectors, and incident-level correlation to determine with high confidence that an attack is in progress and which assets are compromised. Automatic attack disruption then automatically restricts compromised identities through Defender and identity enforcement mechanisms — Contain user (endpoint layer), Disable user, Revoke user session and Suspend user in Entra — without individual runtime analyst approval. The AI/model system materially contributes to determining that intervention is required; the final enforcement is performed by deterministic Defender/identity infrastructure.
Recorded characteristics
- Function
- Microsoft documents that "Microsoft Defender correlates millions of individual signals to identify active ransomware campaigns or other sophisticated attacks in the environment with high confidence" and that, while an attack is in progress, "Defender disrupts the attack by automatically containing compromised assets that the attacker is using". "It automatically takes response actions in relevant Microsoft Defender products to contain the attack in real-time by containing and disabling affected assets." Recorded chain: Defender XDR cross-workload security signals → ML/model outputs, detectors and incident-level correlation → high-confidence attack/compromised-asset determination → automatic attack-disruption response → Defender/identity enforcement mechanism → identity/account/session restriction. The four identity effects in scope are distinct and do not necessarily occur together: (1) Contain user — "The contain user action enforces user containment at the endpoint layer" (Defender for Endpoint); this is not the same as disabling the identity account. (2) Disable user — "Disables the user account to prevent further sign-in and access" (Defender for Identity); "an automatic suspension of a compromised account to prevent additional damage, such as lateral movement, malicious mailbox use, or malware execution." (3) Revoke user session — "Revokes active user sessions to interrupt access" (Microsoft Entra ID). (4) Suspend user in Entra — "Suspends the user account in Microsoft Entra ID to prevent further access." No generative model directly manipulates the identity system.
- Data access
- Microsoft states attack disruption uses "high-fidelity signals and incident-level correlation from real data from email, identity, applications, documents, devices, networks, and files" and "considers signals from different sources to determine compromised assets", correlating signals "from endpoints, identities, email and collaboration tools, and SaaS apps". The actions change state in Active Directory, Microsoft Entra ID and Defender-managed endpoints.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Not required
- Permission basis
- Mixed
- Administrative control
- Human confirmation: automatic attack-disruption actions can execute without individual runtime analyst approval ("automatically takes response actions"; "built in"). Prior configuration, deployment, exclusions, licensing and administrative settings are not runtime human confirmation, and post-action investigation or reversal does not change this classification. Exclusions: "If you have critical assets that shouldn't be automatically contained, you can configure exclusions for supported users, devices, and IP addresses." Reversal: "all automatic actions can be undone by your security team". Visibility: the incident "shows a dedicated disruption tag, highlights the status of the assets contained in the incident graph, and adds an action to the Action Center"; incidents likely to be automatically disrupted carry "(attack disruption)" in their titles via the API. Permission basis (mixed) — two or more distinct documented runtime execution mechanisms, neither of which is the invoking user's authority, and neither of which is documented as a dedicated identity of the AI itself: on-premises Active Directory — "By default, the Defender for Identity sensor impersonates the LocalSystem account of the domain controller and performs the actions"; this "can be changed", and configured action accounts are also supported; Entra-only (cloud-native) accounts — "Defender for Identity executes the disable user action in Microsoft Entra ID by using a Microsoft‑managed enterprise application" named Microsoft Defender for Identity (application ID 60ca1954‑583c‑4d1f‑86de‑39d835f3e452); synchronised accounts (hosted in Active Directory and synced to Entra ID) — "Defender for Identity triggers the disable user action via onboarded domain controllers". No universal execution identity across environments is established.
- Default state
- Enabled
- Availability
- Microsoft describes automatic attack disruption as "built in" and as acting automatically; the reviewed evidence does not require an administrator to switch the capability on first, so the Registry records the default as enabled. Actual operation depends on applicable technical and licensing prerequisites — for example Defender for Identity "requires domain controller auditing and properly configured action accounts", and Defender for Cloud Apps "requires a properly configured Microsoft Office 365 connector" — and administrators can configure exclusions. Under Registry methodology these prerequisites and configuration options do not change the default-state classification.
- Licensing
- The configure page directs organisations to "review the prerequisites for licensing, permissions, and product-specific setup requirements". Detailed licence mapping per identity action is not recorded here.
- External model or provider
- Microsoft states that "Attack disruption AI uses an ensemble of specialized models and detectors developed across the Microsoft Defender suite" and that "The platform uses multiple machine learning approaches, including graph models, boosted decision trees, neural networks, and dedicated small language models (SLMs), to improve detection quality and action precision." Defender classifies detector hits "by combining machine learning outputs, cross-workload correlation, and expert-led incident classification" (expert-led classification is part of detector tuning and validation, not runtime approval). Microsoft's own models; no external model provider documented.
- Limitations and uncertainty
- Out of scope: predictive shielding (including proactive user containment, GPO and Safeboot hardening), the Okta and AWS IAM attack-disruption integrations (preview, via Microsoft Sentinel), automatic device isolation and device containment, Security Copilot, general Defender automated investigation and response, and arbitrary identity administration. The record does not claim that Security Copilot makes the containment decision, that every disruption decision uses an SLM, that an SLM chooses between Disable user and Revoke user session, that one particular model selects every enforcement action, or that the complete model/action-selection mechanism is publicly documented; the exact internal mechanism for selecting individual enforcement actions is Not Publicly Established. Automation-level limitation: the configure page states that device-group automation settings "determine whether automated investigations run and whether remediation actions are taken automatically or only after approval", that "Selecting the Semi automation level allows triggering of automatic attack disruption without the need for manual approval", and that a device group can be excluded "from automated containment" by setting "no automated response"; this wording concerns device groups and is not generalised into a claim that identity actions require approval. Manual remediation actions in Defender for Identity that prompt for confirmation are separate from automatic attack disruption and are not attributed to it. Reversibility: only that the security team can undo automatic actions is recorded; universal automatic restoration, automatic expiry of account disablement, automatic false-positive recovery and universal rollback semantics are not claimed. Blast radius: multiple assets can be affected within a disrupted incident; the maximum number of identities affected is Not Publicly Established. Auditability: incident tags, the incident graph and Action Center entries are documented; complete AI-decision provenance (model input → output → confidence → action selection → execution principal → target-side result → reversal) is not claimed as one chain. Not Publicly Established: the exact model selecting a particular identity action; weighting of ML versus deterministic detectors for individual decisions; whether every identity event involves an SLM; internal decision thresholds beyond Microsoft's published descriptions; maximum identities per incident and any numerical blast-radius limit; sequencing of multiple identity actions; whether session revocation always accompanies account disablement; exactly-once execution; duplicate-action suppression; retry counts; transactional consistency between AD and Entra; automatic rollback after partial enforcement; universal automatic user restoration; complete model/version attribution; complete AI decision provenance; universal execution identity across environments.
Evidence
- Automatic attack disruption in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn
Supports: Function · Actions · External actions · Human confirmation · Permission basis · Default state · External model · Admin controls · Limitations · Primary source
Correlates signals into high-confidence incidents and automatically contains compromised assets.
Contain user (endpoint layer), Disable user, Revoke user session, Suspend user in Entra — listed as distinct actions.
Actions executed via Defender for Endpoint, Defender for Identity and Microsoft Entra ID.
"automatically takes response actions"; built-in automatic disruption; actions can be undone.
Disable user runs via domain controllers (AD/synced) or a Microsoft-managed enterprise application (Entra-only).
Described as "built in" and acting automatically.
Ensemble of models and detectors: graph models, boosted decision trees, neural networks, SLMs.
Exclusions for supported users, devices and IP addresses; undo by security team; Action Center entry.
Predictive shielding contain user applied differently; Okta/AWS preview integrations.
- Configure automatic attack disruption in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learn
Supports: Permission basis · Admin controls · Availability · Limitations · Primary source
Defender for Identity sensor impersonates domain controller LocalSystem by default; action accounts supported.
Device-group automation levels (Semi; no automated response) and exclusions.
Prerequisites: DC auditing, action accounts, Office 365 connector, licensing.
Automation-level wording applies to device groups.
- Remediation Actions for Compromised Users in Microsoft Defender for Identity - Microsoft Defender for Identity | Microsoft Learn
Supports: Permission basis · Limitations · Primary source
Microsoft-managed enterprise application executes remediation actions in Entra ID.
Manual remediation actions prompt for confirmation; separate from automatic disruption.