Remove-MDEAppExecution

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook will remove restrict app execution on the machine in Microsoft Defender for Endpoint.

Attribute Value
Type Playbook
Solution Standalone Content
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 3
wdatp Managed 1 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Hosts post /entities/host —
Add_comment_to_incident_(V3) post /Incidents/Comment —
Add_comment_to_incident_(V3)_2 post /Incidents/Comment —

wdatp (Managed)

Action Method Endpoint Other
Actions_-_Remove_app_execution_restriction post /api/machines/@{encodeURIComponent(items('For_each')?['MdatpDeviceId'])}/unrestrictCodeExecution —

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks