Skip to main content
Stop execution of a file on a device and delete it. The following permissions are required to run this action:
  • Machine.StopAndQuarantine
  • Machine.ReadWrite.All
External DocumentationTo learn more, visit the Microsoft Defender for Endpoint documentation.

Parameters

Example Output

Workflow Library Example

Stop and Quarantine File with Microsoft Defender for Endpoint and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop