Microsoft Defender XDR
Microsoft's extended detection and response suite, which correlates security signals across endpoints, identities, email and collaboration tools and SaaS apps into incidents. Automatic attack disruption is built into this product.
AI capabilities recorded
- Automatic attack disruption — AI-directed identity containment
Active · verified 2026-10-02
Microsoft Defender XDR correlates cross-workload security signals using machine-learning outputs, specialised models and detectors, and incident-level correlation to determine with high confidence that an attack is in progress and which assets are compromised. Automatic attack disruption then automatically restricts compromised identities through Defender and identity enforcement mechanisms — Contain user (endpoint layer), Disable user, Revoke user session and Suspend user in Entra — without individual runtime analyst approval. The AI/model system materially contributes to determining that intervention is required; the final enforcement is performed by deterministic Defender/identity infrastructure.