Approve Actions
The BlueVoyant Security Operations Center (SOC) can do approved recommended actions in response to events. Actions that you approve during Onboarding will help the SOC resolve incidents faster and more consistently, decrease false positive escalations, assess risk better, and enrich your portal data.
If you do not approve an action, BlueVoyant SOC will escalate each incident for which this action is recommended. Your SOC or IT team can then do the action to comply with your security policies.
If you approve an action, and there was a successful malicious event or BlueVoyant SOC has high confidence of a potential malicious event, BlueVoyant will run the Containment Action. Then we will then escalate the incident with a report on the actions done and why, for you to inspect.
In Containment Actions:
Select a Quick Setup Template, OR
Read each action and select the actions to approve, OR
Select a template and then change the selections
Click .
Containment Actions
If these actions are pre-approved, the SOC analysts can run them to quickly contain endpoints, user accounts, and emails to prevent the spread or malicious actions.
Endpoint Actions - Require active and onboarded Microsoft Defender for Endpoint
Identity Actions - Require active Microsoft Defender for Identity
Identity > Force Password Reset - Self-service password resets (SSPR) must be enabled for users to reset their own password.
Email Security - Requires Microsoft Defender for Office
Containment Actions | Description | Tool |
|---|---|---|
Isolate Machine | Isolates compromised workstations and servers from the network but keeps a management connection to investigate, remediate, and release the endpoint. | EDR |
Contain Rogue Device | Contains (restricts the network access of) unmanaged or unauthorized devices that may run attacks on monitored endpoints. | EDR |
Restrict App Execution on Endpoint | Restricts endpoints to run only Microsoft-signed code through App Control for Business. | MDE |
Containment Actions | Description | Tool |
|---|---|---|
Block File Hash | Blocks execution of files that match specified hash values on all managed endpoints. | EDR |
Block Network IP | Blocks network traffic to and from specified IP addresses. | EDR |
Block Domain | Blocks network traffic to and from specified domains. | EDR |
Containment Actions | Description | Tool |
|---|---|---|
Disable User | Disables compromised Active Directory and hybrid user accounts that use MDR sensor. | MDI |
Disable Account | Disables sign-in for cloud-only user accounts. This Containment Action is usually done with Force Password Reset and Confirm Compromised User. | Entra ID |
Force Password Reset | Forces users to reset their passwords on the next sign-in for cloud-only user accounts. This Containment Action is usually done with Confirm Compromised User. | Entra ID |
Delete Rogue MFA Device | Removes unauthorized MFA devices registered to compromised user accounts. | Entra ID |
Dismiss Risky User | Dismisses risk detection for a user account when the risk classification is False Positive. This releases a user account from a Risky User security group configured by Entra ID Protection. | Entra ID |
Confirm Compromised User | Confirms that a user account was compromised and starts automated response policies. This moves a user account into a Risky User security group configured by Entra ID Protection. This Containment Action is usually done with Force Password Reset. | Entra ID |
Containment Actions | Description | Tool |
|---|---|---|
Purge Malicious Email | Removes malicious emails from all user mailboxes. | M365 |
Delete Malicious Email Rule | Deletes malicious inbox rules created by malicious actors. | M365 |
Block Email on Tenant | Blocks specified email addresses from sending to the tenant. | M365 |
Block Domain on Tenant | Blocks all emails from specified domains at the tenant level. | M365 |