Automatic attack disruption: which product acts, by identity type

Verdict: The disruption executor depends on where the identity lives. Defender for Identity handles AD, hybrid and cloud accounts by different mechanisms. Cloud Apps handles OAuth apps. AWS IAM gets a deny policy via the Sentinel connector.

CriterionOn-prem AD accountHybrid synced accountCloud-only Entra accountOAuth applicationAWS IAM identity
ExecutorDefender for IdentityDefender for Identity + attack disruptionDefender for IdentityDefender for Cloud AppsSentinel AWS connector
MechanismDisable via onboarded domain controllersDC disable plus disable in Entra IDMicrosoft-managed enterprise app, RBAC-validatedProtective measures on the OAuth appAttach a deny policy to the user or federated role

Rules

Traps