Skip to content

Device Containment

Device Containment

Device containment is a planned Challenge capability shown on the Integrations page as Coming soon. It is not available for configuration or execution in the product today.

Planned capability

When released, device containment integrations are intended to let incident responders trigger actions such as:

  • MDM device lock — Remotely lock managed endpoints from your mobile device management platform.
  • EDR isolation — Initiate endpoint isolation or containment in your detection and response tooling.

These actions would complement session revocation, which addresses IdP and SaaS sessions, by targeting the endpoint itself during account takeover or impersonation investigations.

Current status

The Integrations page displays a placeholder section describing future MDM locks and EDR isolation. No credentials, API keys, or responder actions are wired to device containment yet.

Use Session Revocation and Responder for available containment workflows today.

Stay informed

For early access or product updates, contact [email protected].