It appears there is no capability for Isolation on macOS, same with IOC Scans?
Is this true, and if it is, are those features being worked on?
The initial rollout of endpoint isolation is in the Windows connector. There are plans to extend this to the macOS and Linux connectors, but no precise dates that I can share at this point.
The Windows-specific Endpoint IOC scan feature has been there for a long time. There's some work under way (see the current open beta of Orbital Advanced Search for example) to add capabilities here, and again it's likely that this will show up for Windows first, and the other OS connectors to follow at a later point.
The prioritization is mainly a matter of Windows still being the leading target of attacks, as well as the largest chunk of the AMP connector installed base, so that's where the need is generally most acute.
Are you saying that Cisco has a single A4E software development team across all the desktop platforms (Windows\Linux\MacOS), and that they only advance one connector at a time?