Perform bulk isolation for endpoints managed by Windows Defender for Endpoint

  • Thread starter Thread starter MoShahin
  • Start date Start date
M

MoShahin

Guest
Hi Everyone, I have been recently studying the implementation of Defender for Endpoint API to perform bulk isolation/release for endpoints. This documentation (Isolate machine API) states a limitation of 100 calls/minute and 1500 calls/hour. So I have to think of another way to overcome this. API structure uses endpoint ID as follows: POST https://api.securitycenter.microsoft.com/api/machines/{id}/isolateOne of the things I thought of is that if I can run this API and fill in a 'Device Group' ID instead o

Continue reading...
 
Back
Top