diff --git a/windows/keep-secure/images/atp-notification-isolate.png b/windows/keep-secure/images/atp-notification-isolate.png new file mode 100644 index 0000000000..83bfced41d Binary files /dev/null and b/windows/keep-secure/images/atp-notification-isolate.png differ diff --git a/windows/keep-secure/respond-machine-alerts-windows-defender-advanced-threat-protection.md b/windows/keep-secure/respond-machine-alerts-windows-defender-advanced-threat-protection.md index abc40d1187..f5dcbb1eda 100644 --- a/windows/keep-secure/respond-machine-alerts-windows-defender-advanced-threat-protection.md +++ b/windows/keep-secure/respond-machine-alerts-windows-defender-advanced-threat-protection.md @@ -63,7 +63,7 @@ When the isolation configuration is applied, there will be a new event in the ma **Notification on machine user**:
When a machine is being isolated, the following notification is displayed to inform the user that the machine is being isolated from the network: -![Image of no network connection](images/atp-no-network-connection.png) +![Image of no network connection](images/atp-notification-isolate.png) ## Undo machine isolation Depending on the severity of the attack and the state of the machine you can choose to release the machine isolation after you have verified that the compromised machine has been remediated.