The Orbital Agent's isolation feature allows for a rapid response to security incidents by isolating the device affected to prevent the threat from spreading to other systems in your network/organisation. It also preserves evidence on the device, making it easier to investigate and respond effectively. To isolate a device, simply follow the steps outlined below.
Log in to your my.defense.com account.
Select Endpoints from the navigation on the left-hand side.
Click Orbital Agent from the sub-navigation.
Find the device you wish to isolate by using the search features, you can search by hostname and current user, as well as filter by group using the Select Group dropdown menu.
When you have found the device, click on the name to go to that device's endpoint page.
Select Isolate on the top right of the page.
And that's it! You've successfully isolated the device using Orbital's isolation feature π
