Configure Microsoft Defender for Endpoint for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can contain perform host-based response actions in your network using Microsoft Defender for Endpoint®.
Full containment functionality is available for these Microsoft Defender for Endpoint versions:
- Microsoft Defender for Endpoint Commercial
- Microsoft Defender for Endpoint for Government Community Cloud (GCC)
Microsoft Defender for Endpoint supports these response actions:
- Contain a host/Remove from containment
For more information, see Response action descriptions.
Note: Arctic Wolf only supports full containment. Selective containment is unsupported.
These resources are required:
- A user account with Global Administrator permissions
-
A supported license and operating system, as outlined in Minimum requirements for Microsoft Defender for Endpoint
- Contact your CST to validate the Active Response integration. Have a device or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.