05-15-2020 08:13 AM
Been a user of AMP for sometime but installed and left to do its own thing for quite a while. Been focusing in recent weeks updating connectors and reviewing settings and came across a question couldn't find the answer to and thats how to Isolate a Computer.
In the help text it states
Isolating an endpoint blocks all network traffic except for communication to the AMP Cloud and any other IP addresses configured in your IP isolation allow list.
To start an Endpoint Isolation session:
1. | In the console, navigate to Management > Computers. |
2. | Locate the computer you want to isolate and click to display details. |
3. | Click the Start Isolation button. |
The Connector UI will indicate that the endpoint is isolated.
I cannot see the Start Button to start isolation, anyone else have the same issue?
Thanks
Solved! Go to Solution.
05-15-2020 08:53 AM
You need to be on Windows Connector version 7.0.5 or higher and have isolation enabled in your policy. Then, you should see the Start Isolation button.
Thanks,
Matt
05-25-2020 04:56 AM
Hello @soup_dragon,
AMP for endpoints also includes automated actions, where you can automate the isolation based on generated IOCs.
Greetings,
Thorsten
05-15-2020 08:53 AM
You need to be on Windows Connector version 7.0.5 or higher and have isolation enabled in your policy. Then, you should see the Start Isolation button.
Thanks,
Matt
05-15-2020 10:04 AM
Perfect, in fact I was missing the button but missed it needed to be setup in Policy, help text didn't mention that. Have now switched on for all active polices. Thanks for the quick response.
05-25-2020 04:56 AM
Hello @soup_dragon,
AMP for endpoints also includes automated actions, where you can automate the isolation based on generated IOCs.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide