Microsoft · Microsoft Defender XDR

Automatic attack disruption — AI-directed identity containment

Microsoft Defender XDR correlates cross-workload security signals using machine-learning outputs, specialised models and detectors, and incident-level correlation to determine with high confidence that an attack is in progress and which assets are compromised. Automatic attack disruption then automatically restricts compromised identities through Defender and identity enforcement mechanisms — Contain user (endpoint layer), Disable user, Revoke user session and Suspend user in Entra — without individual runtime analyst approval. The AI/model system materially contributes to determining that intervention is required; the final enforcement is performed by deterministic Defender/identity infrastructure.

Recorded characteristics

Function
Microsoft documents that "Microsoft Defender correlates millions of individual signals to identify active ransomware campaigns or other sophisticated attacks in the environment with high confidence" and that, while an attack is in progress, "Defender disrupts the attack by automatically containing compromised assets that the attacker is using". "It automatically takes response actions in relevant Microsoft Defender products to contain the attack in real-time by containing and disabling affected assets." Recorded chain: Defender XDR cross-workload security signals → ML/model outputs, detectors and incident-level correlation → high-confidence attack/compromised-asset determination → automatic attack-disruption response → Defender/identity enforcement mechanism → identity/account/session restriction. The four identity effects in scope are distinct and do not necessarily occur together: (1) Contain user — "The contain user action enforces user containment at the endpoint layer" (Defender for Endpoint); this is not the same as disabling the identity account. (2) Disable user — "Disables the user account to prevent further sign-in and access" (Defender for Identity); "an automatic suspension of a compromised account to prevent additional damage, such as lateral movement, malicious mailbox use, or malware execution." (3) Revoke user session — "Revokes active user sessions to interrupt access" (Microsoft Entra ID). (4) Suspend user in Entra — "Suspends the user account in Microsoft Entra ID to prevent further access." No generative model directly manipulates the identity system.
Data access
Microsoft states attack disruption uses "high-fidelity signals and incident-level correlation from real data from email, identity, applications, documents, devices, networks, and files" and "considers signals from different sources to determine compromised assets", correlating signals "from endpoints, identities, email and collaboration tools, and SaaS apps". The actions change state in Active Directory, Microsoft Entra ID and Defender-managed endpoints.
Actions
Can take actions
External actions
Yes
Human confirmation
Not required
Permission basis
Mixed
Administrative control
Human confirmation: automatic attack-disruption actions can execute without individual runtime analyst approval ("automatically takes response actions"; "built in"). Prior configuration, deployment, exclusions, licensing and administrative settings are not runtime human confirmation, and post-action investigation or reversal does not change this classification. Exclusions: "If you have critical assets that shouldn't be automatically contained, you can configure exclusions for supported users, devices, and IP addresses." Reversal: "all automatic actions can be undone by your security team". Visibility: the incident "shows a dedicated disruption tag, highlights the status of the assets contained in the incident graph, and adds an action to the Action Center"; incidents likely to be automatically disrupted carry "(attack disruption)" in their titles via the API. Permission basis (mixed) — two or more distinct documented runtime execution mechanisms, neither of which is the invoking user's authority, and neither of which is documented as a dedicated identity of the AI itself: on-premises Active Directory — "By default, the Defender for Identity sensor impersonates the LocalSystem account of the domain controller and performs the actions"; this "can be changed", and configured action accounts are also supported; Entra-only (cloud-native) accounts — "Defender for Identity executes the disable user action in Microsoft Entra ID by using a Microsoft‑managed enterprise application" named Microsoft Defender for Identity (application ID 60ca1954‑583c‑4d1f‑86de‑39d835f3e452); synchronised accounts (hosted in Active Directory and synced to Entra ID) — "Defender for Identity triggers the disable user action via onboarded domain controllers". No universal execution identity across environments is established.
Default state
Enabled
Availability
Microsoft describes automatic attack disruption as "built in" and as acting automatically; the reviewed evidence does not require an administrator to switch the capability on first, so the Registry records the default as enabled. Actual operation depends on applicable technical and licensing prerequisites — for example Defender for Identity "requires domain controller auditing and properly configured action accounts", and Defender for Cloud Apps "requires a properly configured Microsoft Office 365 connector" — and administrators can configure exclusions. Under Registry methodology these prerequisites and configuration options do not change the default-state classification.
Licensing
The configure page directs organisations to "review the prerequisites for licensing, permissions, and product-specific setup requirements". Detailed licence mapping per identity action is not recorded here.
External model or provider
Microsoft states that "Attack disruption AI uses an ensemble of specialized models and detectors developed across the Microsoft Defender suite" and that "The platform uses multiple machine learning approaches, including graph models, boosted decision trees, neural networks, and dedicated small language models (SLMs), to improve detection quality and action precision." Defender classifies detector hits "by combining machine learning outputs, cross-workload correlation, and expert-led incident classification" (expert-led classification is part of detector tuning and validation, not runtime approval). Microsoft's own models; no external model provider documented.
Limitations and uncertainty
Out of scope: predictive shielding (including proactive user containment, GPO and Safeboot hardening), the Okta and AWS IAM attack-disruption integrations (preview, via Microsoft Sentinel), automatic device isolation and device containment, Security Copilot, general Defender automated investigation and response, and arbitrary identity administration. The record does not claim that Security Copilot makes the containment decision, that every disruption decision uses an SLM, that an SLM chooses between Disable user and Revoke user session, that one particular model selects every enforcement action, or that the complete model/action-selection mechanism is publicly documented; the exact internal mechanism for selecting individual enforcement actions is Not Publicly Established. Automation-level limitation: the configure page states that device-group automation settings "determine whether automated investigations run and whether remediation actions are taken automatically or only after approval", that "Selecting the Semi automation level allows triggering of automatic attack disruption without the need for manual approval", and that a device group can be excluded "from automated containment" by setting "no automated response"; this wording concerns device groups and is not generalised into a claim that identity actions require approval. Manual remediation actions in Defender for Identity that prompt for confirmation are separate from automatic attack disruption and are not attributed to it. Reversibility: only that the security team can undo automatic actions is recorded; universal automatic restoration, automatic expiry of account disablement, automatic false-positive recovery and universal rollback semantics are not claimed. Blast radius: multiple assets can be affected within a disrupted incident; the maximum number of identities affected is Not Publicly Established. Auditability: incident tags, the incident graph and Action Center entries are documented; complete AI-decision provenance (model input → output → confidence → action selection → execution principal → target-side result → reversal) is not claimed as one chain. Not Publicly Established: the exact model selecting a particular identity action; weighting of ML versus deterministic detectors for individual decisions; whether every identity event involves an SLM; internal decision thresholds beyond Microsoft's published descriptions; maximum identities per incident and any numerical blast-radius limit; sequencing of multiple identity actions; whether session revocation always accompanies account disablement; exactly-once execution; duplicate-action suppression; retry counts; transactional consistency between AD and Entra; automatic rollback after partial enforcement; universal automatic user restoration; complete model/version attribution; complete AI decision provenance; universal execution identity across environments.

Evidence