sophos_isolate_endpoint
Isolate an endpoint from the network to contain a compromised machine, restricting communication to Sophos Central for incident response.
Instructions
Isolate an endpoint from the network. The endpoint will only be able to communicate with Sophos Central. Use this for incident response to contain a compromised machine.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| comment | No | Reason for isolating the endpoint | |
| tenant_id | Yes | Target tenant ID | |
| endpoint_id | Yes | Endpoint ID to isolate |