update images
After Width: | Height: | Size: 18 KiB |
Before Width: | Height: | Size: 67 KiB After Width: | Height: | Size: 48 KiB |
After Width: | Height: | Size: 21 KiB |
After Width: | Height: | Size: 16 KiB |
After Width: | Height: | Size: 17 KiB |
After Width: | Height: | Size: 17 KiB |
@ -108,7 +108,7 @@ The action to restrict an application from running applies a code integrity poli
|
||||

|
||||
|
||||
The Action center shows the submission information:
|
||||
[NEED IMAGE HERE OF APP RESTRICTION]
|
||||

|
||||
|
||||
|
||||
- **Submission time** - Shows when the isolation action was submitted.
|
||||
@ -163,6 +163,9 @@ The package contains the following folders:
|
||||
|
||||
3. Type a comment and select **Yes, collect package** to take action on the machine.
|
||||
|
||||

|
||||
|
||||
|
||||
The Action center shows the submission information:
|
||||

|
||||
|
||||
@ -191,13 +194,17 @@ As part of the investigation or response process, you can remotely initiate an a
|
||||
- **Machines list** - Select the machine name from the list of machines.
|
||||
- **Search box** - Select Machine from the drop-down menu and enter the machine name.
|
||||
2. Open the **Actions** menu and select **Run antivirus scan**.
|
||||
[INSERT SCREEN CAPTURE OF ACTION BUTTON HERE!!!]
|
||||
3. Select the scan type that you'd like to run. You can choose between a quick or a full scan.
|
||||

|
||||
|
||||
4. Type a comment (optional) and select **Yes** to start the scan.
|
||||
|
||||
3. Select the scan type that you'd like to run. You can choose between a quick or a full scan.
|
||||

|
||||
|
||||
|
||||
4. Type a comment and select **Yes, run scan** to start the scan.
|
||||
|
||||
The Action center shows the scan information:
|
||||
[INSERT SCREEN CAPTURE OF POP UP HERE]
|
||||

|
||||
|
||||
- **Submission time** - Shows when the isolation action was submitted.
|
||||
- **Submitting user** - Shows who submitted the action on the machine. You can view the comments provided by the user by selecting the information icon.
|
||||
@ -206,7 +213,14 @@ As part of the investigation or response process, you can remotely initiate an a
|
||||
The machine timeline will include a new event, reflecting that a scan action was submitted on the machine as well as an event when a scan has completed. Windows Defender AV alerts will reflect any detections that surfaced during the scan.
|
||||
|
||||
## Check activity details in Action center
|
||||
The **Action center** provides information on actions that were taken on a machine or file. You’ll be able to view if a machine was isolated and if an investigation package is available from a machine. All related details are also shown, for example, submission time, submitting user, and if the action succeeded or failed.
|
||||
The **Action center** provides information on actions that were taken on a machine or file. You’ll be able to view the following details:
|
||||
|
||||
- Investigation package collection
|
||||
- Antivirus scan
|
||||
- App restriction
|
||||
- Machine isolation
|
||||
|
||||
All other related details are also shown, for example, submission time, submitting user, and if the action succeeded or failed.
|
||||
|
||||

|
||||
|
||||
|