Microsoft Defender for Endpoint now uses automatic attack disruption to isolate compromised user accounts and block lateral movement in hands-on-keyboard attacks with the help of a new ‘contain user’ capability in public preview. […]

from https://www.bleepingcomputer.com/news/security/microsoft-defender-now-auto-isolates-compromised-accounts/