diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md index c79fa83c94..5faa671548 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md @@ -60,6 +60,7 @@ Response actions run along the top of a specific machine page and include: - Run antivirus scan - Restrict app execution - Isolate machine +- Consult a threat expert - Action center You can take response actions in the Action center, in a specific machine page, or in a specific file page.