An administrator needs to isolate a compromised device from the network while keeping it connected to the Defender for Endpoint service for investigation. Which action should they take in the Microsoft 365 Defender portal?
-
A
Run antivirus scan
-
B
Contain device
-
C
Offboard device
-
D
Restrict app execution