Device Containment
Device Containment
Device containment is a planned Challenge capability shown on the Integrations page as Coming soon. It is not available for configuration or execution in the product today.
Planned capability
When released, device containment integrations are intended to let incident responders trigger actions such as:
- MDM device lock — Remotely lock managed endpoints from your mobile device management platform.
- EDR isolation — Initiate endpoint isolation or containment in your detection and response tooling.
These actions would complement session revocation, which addresses IdP and SaaS sessions, by targeting the endpoint itself during account takeover or impersonation investigations.
Current status
The Integrations page displays a placeholder section describing future MDM locks and EDR isolation. No credentials, API keys, or responder actions are wired to device containment yet.
Use Session Revocation and Responder for available containment workflows today.
Stay informed
For early access or product updates, contact [email protected].