Automatic attack disruption: which product acts, by identity type
Verdict: The disruption executor depends on where the identity lives. Defender for Identity handles AD, hybrid and cloud accounts by different mechanisms. Cloud Apps handles OAuth apps. AWS IAM gets a deny policy via the Sentinel connector.
| Criterion | On-prem AD account | Hybrid synced account | Cloud-only Entra account | OAuth application | AWS IAM identity |
|---|---|---|---|---|---|
| Executor | Defender for Identity | Defender for Identity + attack disruption | Defender for Identity | Defender for Cloud Apps | Sentinel AWS connector |
| Mechanism | Disable via onboarded domain controllers | DC disable plus disable in Entra ID | Microsoft-managed enterprise app, RBAC-validated | Protective measures on the OAuth app | Attach a deny policy to the user or federated role |
Rules
- For an account hosted only in Entra ID, Defender for Identity disables it through a Microsoft-managed enterprise application that validates the signed-in user's RBAC first.
- For a hybrid account synced from AD, Defender for Identity disables it via domain controllers and attack disruption also disables it in Entra ID.
- A compromised OAuth application exfiltrating SaaS data is contained by Defender for Cloud Apps taking protective measures on the app.
- A compromised AWS IAM user is contained by attaching a deny policy to the user or federated role, executed through the Sentinel AWS connector.
- Protect a business-critical asset from automated containment by adding it to the attack disruption exclusion settings for users, devices and IPs.
Traps
- Disabling Defender for Endpoint or removing onboarding to stop containment is not the supported path; configure a targeted exclusion instead.
- Attack disruption evaluates correlated behavioural signals, not hostnames, so renaming a domain controller does not exclude it.