Skip to main content

User Knowledge Base

Approve Actions

The BlueVoyant Security Operations Center (SOC) can do approved recommended actions in response to events. Actions that you approve during Onboarding will help the SOC resolve incidents faster and more consistently, decrease false positive escalations, assess risk better, and enrich your portal data.  

If you do not approve an action, BlueVoyant SOC will escalate each incident for which this action is recommended. Your SOC or IT team can then do the action to comply with your security policies. 

If you approve an action, and there was a successful malicious event or BlueVoyant SOC has high confidence of a potential malicious event, BlueVoyant will run the Containment Action. Then we will then escalate the incident with a report on the actions done and why, for you to inspect.

To approve actions:
  1. In Containment Actions:

    • Select a Quick Setup Template, OR

    • Read each action and select the actions to approve, OR

    • Select a template and then change the selections

  2. Click Continue.

Containment Actions

If these actions are pre-approved, the SOC analysts can run them to quickly contain endpoints, user accounts, and emails to prevent the spread or malicious actions.

Prerequisites
  • Endpoint Actions - Require active and onboarded Microsoft Defender for Endpoint

  • Identity Actions - Require active Microsoft Defender for Identity

  • Identity > Force Password Reset - Self-service password resets (SSPR) must be enabled for users to reset their own password.

  • Email Security - Requires Microsoft Defender for Office

Table 1. Endpoint Actions

Containment Actions

Description

Tool

Isolate Machine

Isolates compromised workstations and servers from the network but keeps a management connection to investigate, remediate, and release the endpoint.

EDR

Contain Rogue Device

Contains (restricts the network access of) unmanaged or unauthorized devices that may run attacks on monitored endpoints.

EDR

Restrict App Execution on Endpoint

Restricts endpoints to run only Microsoft-signed code through App Control for Business.

MDE



Table 2. Threat Intelligence Actions

Containment Actions

Description

Tool

Block File Hash

Blocks execution of files that match specified hash values on all managed endpoints.

EDR

Block Network IP

Blocks network traffic to and from specified IP addresses.

EDR

Block Domain

Blocks network traffic to and from specified domains.

EDR



Table 3. Identity Actions

Containment Actions

Description

Tool

Disable User

Disables compromised Active Directory and hybrid user accounts that use MDR sensor.

MDI

Disable Account

Disables sign-in for cloud-only user accounts. This Containment Action is usually done with Force Password Reset and Confirm Compromised User.

Entra ID

Force Password Reset

Forces users to reset their passwords on the next sign-in for cloud-only user accounts. This Containment Action is usually done with Confirm Compromised User.

Entra ID

Delete Rogue MFA Device

Removes unauthorized MFA devices registered to compromised user accounts.

Entra ID

Dismiss Risky User

Dismisses risk detection for a user account when the risk classification is False Positive. This releases a user account from a Risky User security group configured by Entra ID Protection.

Entra ID

Confirm Compromised User

Confirms that a user account was compromised and starts automated response policies. This moves a user account into a Risky User security group configured by Entra ID Protection. This Containment Action is usually done with Force Password Reset.

Entra ID



Table 4. Email Actions

Containment Actions

Description

Tool

Purge Malicious Email

Removes malicious emails from all user mailboxes.

M365

Delete Malicious Email Rule

Deletes malicious inbox rules created by malicious actors.

M365

Block Email on Tenant

Blocks specified email addresses from sending to the tenant.

M365

Block Domain on Tenant

Blocks all emails from specified domains at the tenant level.

M365