← SC-200: investigation and security operations response
04 / 10 · 40 MIN

Triage and endpoint response

Decide containment and evidence collection with service context.

Concept and mechanism

Severity helps order work but does not replace criticality, scope, and evidence. A privileged account used during closing can need different attention from a test workstation with the same label. Inspect assets, relationships, chronology, and actions already performed. The incident-cases experience is in preview in inspected documentation and coexists with the previous experience; confirm tenant availability. Regardless of interface, distinguish hypothesis, observed activity, and confirmed compromise. Blocking new email delivery does not necessarily remove effects on an endpoint or identity. Response planning needs to cover affected surfaces and criteria for confirming recovery.

Guided application

Before an impactful action, assess urgency and dependencies without creating a universal delay rule. Isolation may be necessary to limit spread, but a full-tunnel VPN can prevent subsequent device communication with the Defender service. Confirm an appropriate management or recovery path and actual action state. Submitting does not mean completing. When containment permits authorized collection, preserve artifacts before reinstalling. Live response requires enablement, permissions, and device scope; the library and signatures do not prove every script is appropriate. Documented signature verification is specific to PowerShell. For a fictional batch, coordinate SOC and operations to distinguish containment, impact, and recovery.

IN PRACTICE

An action is pending: report the request and ongoing verification without declaring proven containment.

Common pitfalls

Severity as complete context; button as effect; reinstalling before available evidence collection; signature as functional safety.

Related topics: Identity, content, and handover · KQL for reasoning about events

Take this idea with you

Confirm both action outcome and the ability to continue operation and investigation.

Create account

Reference: Device response actions · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately