Microsoft Defender XDR
General

Exclude assets from automated response in attack disruption

In brief

The article now explains exclusion policies, adds permission requirements for device and identity exclusions, clarifies policy application and IP exclusion steps, and recommends excluding specific assets rather than opting out entirely.

What Defender admins need to know

Administrators can more easily identify required permissions and configure exclusions while limiting the security risk of broad opt-outs.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Microsoft Defender XDR rebranding]

This article provides information on howUse exclusion policies to exclude assets from being automatically contained byprevent automatic attack disruption in Microsoft Defender XDR.XDR from applying selected responses to specific assets.

Automatic attack disruption and exclusion policies work together to help contain and control active cyber threats. AttackAutomatic attack disruption is a built-in extendedin, AI-powered capability that automatically contains ongoing attacks by isolatinganalyzes attacker intent and identifies compromised assets (likeassets. It can isolate devices or disable user accounts) in real time, thereby haltingaccounts to stop an attacker’s progress.ongoing attack. Exclusion policies allowlet security teams to designate certainexempt specific assets or actions to be exempt from these automated responses – forresponses. For example, ensuring that specificyou can prevent critical servers from being isolated or critical accounts are not automatically shut down or isolated –from being disabled to avoid unintended business disruption. You can remove exclusions at any time to allowinclude assets to be included in automated responses again.

Device exclusions

The following table lists the permissions required to manage device exclusions.

Unified RBAC for endpoints Required permission
Disabled Security Administrator or Global Administrator role in Microsoft Entra ID or the Microsoft 365 admin center.
Enabled Security Operator (or higher) global Microsoft Entra role, or the Core security settings (manage) permission in Unified RBAC.

For more information,information about enabling Unified RBAC, see Activate Microsoft Defender XDR Unified RBAC.

Identity exclusions

The following table lists the permissions required to manage identity exclusions.

Unified RBAC for identities or endpoints Required permission
Disabled (both identities and endpoints) Security Administrator or Global Administrator role in Microsoft Entra ID or the Microsoft 365 admin center.

:::image type="content" source="media/automatic-attack-disruption-exclusions/attack-disrupt-devices-tab.png" alt-text="Screenshot of the Devices page in automated response settings for attack disruption" lightbox="media/automatic-attack-disruption-exclusions/attack-disrupt-devices-tab.png":::

  1. In the PoloicyPolicy application tab, select Exclude IP to exclude an IP address.

    :::image type="content" source="media/automatic-attack-disruption-exclusions/attack-disrupt-exclude-ip-add.png" alt-text="Screenshot of the IPs tab in automated response settings for attack disruption" lightbox="media/automatic-attack-disruption-exclusions/attack-disrupt-exclude-ip-add-big.png":::

When automatic attack disruption detects with high confidence that a user or device is compromised, it automatically applies containment policies to managed devices in your organization. These policies help contain the threat and stop it from spreading across your environment.

Policy application exclusions give you granular control over how the automatic Attackattack disruption enforcement policies are applied acrossin your environment. It allows customers toThey let you define devices that shouldn't receive specific disruption policies. This provides organizations with the flexibility to protectprotects sensitive, operationally critical, or exception-based systems without fully disabling Automatic Attack Disruption.automatic attack disruption.

Policy applications and exclusions allow you to:

  • Keep most disruption controls active while selectively disabling specific protections
  • Maintain centralized control over which disruption policy controls are enabled or excluded for each tagged group of devices

First create a tag or use an existing tag to define the device or devices. Then create a rule that applies to that tag. For example, you might create a tag for all servers in a specific department and then create a policy application that applies to that tag. By default, all policy controls are enabled. By configuring a policy application for a tagged devices, you can keep disruption enabled and exclude only specific controls for that group.

Create a tag

To create a tag go to Asset rule management in the Microsoft Defender portal and select Create tag. Provide a name and description for the tag, then define dynamic rules to automatically include devices in the tag based on device properties such as device type, operating system, or other attributes.

Create a policy application:application

  1. Go to the Microsoft Defender portal and sign in.

  2. Go to Settings > Microsoft Defender XDR.

To exclude IP addresses from automated responses,create a policy application rule for tagged devices, follow these steps:

  1. Under Automated responses, select Devices.

    :::image type="content" source="media/automatic-attack-disruption-exclusions/create-new-exclusion.png" alt-text="Screenshot of the policy application creation page in automated response settings" lightbox="media/automatic-attack-disruption-exclusions/create-new-exclusion.png":::

  2. Select a tag to apply the policy toto, and then select Next.

  3. Configure the exclusion policydisruption controls you want to disable for the tagged device.devices, and then select Next.

    :::image type="content" source="media/automatic-attack-disruption-exclusions/policy-application-select-controls.png" alt-text="Screenshot of selecting controls to disable for a policy application rule" lightbox="media/automatic-attack-disruption-exclusions/policy-application-select-controls.png":::

Opting out of automatic attack disruption

Opting out of attack disruption can greatly increase security risk. ConsiderInstead of opting out entirely, consider excluding specific entities instead.to limit automated responses only for selected assets.

If you must opt out of attack disruption, open a support case in the Microsoft Defender portal with the subject Attack disruption opt-out. In your request, specify that you wish to opt out of attack disruption and include a brief explanation about your decision. This feedback helps us improve the feature and better understand customer needs. By opting out, you still receive alerts related to attack disruption but no automated actions are taken.