Query Details
# MDE - Device - Isolation Status ## Query Information ### Description DESCRIPTION #### References ### Microsoft 365 Defender ```kql DeviceInfo | extend MitigationStatusObject = parse_json(MitigationStatus) | extend IsolationStatus = MitigationStatusObject.Isolated | where IsolationStatus == "true" ```
This query checks the isolation status of devices in Microsoft 365 Defender. It looks at the MitigationStatus of each device and filters for devices that are currently isolated.

Alex Verboon
Released: June 24, 2024
Tables
Keywords
Operators