Find answers, ask questions, and connect with our
community around the world.

Home Forums Azure SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category Reply To: SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category

  • vnapoli

    Member
    April 14, 2026 at 6:05 pm

    Thank you Lois for the clarification 🙏🏻

    So if I understand correctly, device isolation requires manual approval in AIR, which distinguishes between “low-impact” actions (running a scan, quarantining an email, etc.) and “high-impact” actions such as device.

    ➡️ However, is it true that automatic device isolation is still possible via a Sentinel Playbook or a Defender Custom Detection Rule?

    Also, do you have any other example of high-impact actions that need manual validation in AIR? 👌🏻

Skip to content