Disable Defender for Identity Automation
Hello everyone. I am looking to rollout Defender for Identity in my environment. I am running into concerns regarding the automatic attack disruption feature. Ideally I would want to deploy the solution in a detect only format. However I am not seeing anyway to disable all automated response, or to exclude users in a bulk format. Currently all I was able to find is this exclusion list in within the Defender portal: https://learn.microsoft.com/en-us/defender-for-identity/automated-response-exclusions#how-to-add-automated-response-exclusions
However this list appears to only allow selecting of individual users. Is anyone aware of a way to fully disable all automated actions for Defender for Identity, or of a way to bulk exclude users?
Thanks
Hello everyone. I am looking to rollout Defender for Identity in my environment. I am running into concerns regarding the automatic attack disruption feature. Ideally I would want to deploy the solution in a detect only format. However I am not seeing anyway to disable all automated response, or to exclude users in a bulk format. Currently all I was able to find is this exclusion list in within the Defender portal: https://learn.microsoft.com/en-us/defender-for-identity/automated-response-exclusions#how-to-add-automated-response-exclusions However this list appears to only allow selecting of individual users. Is anyone aware of a way to fully disable all automated actions for Defender for Identity, or of a way to bulk exclude users? Thanks Read More