> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Endpoint Remediation

> Isolate servers and workstations

Endpoint remediation automatically (or manually) isolates endpoints when they are associated with malicious detections. If a detection matches a verdict rule with endpoint remediation actions configured, but endpoint auto-remediation is disabled globally or blocked by group policy, the detection will be escalated to your team.

<Info>
  Auto-remediation is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic remediation and escalate the case to your team instead. Manual remediation remains available.
</Info>

## Remediation Actions

Wirespeed can take the following actions to remediate an endpoint:

* **Isolate Endpoint** — disconnect the endpoint from the network
* **Lock Device** — remotely lock the device screen

Which actions appear in the UI and run for a detection depend on the connected EDR or MDM integration and the actions selected on the matching verdict rule.

## Release Actions

When a detection is resolved as benign, Wirespeed can automatically reverse endpoint remediation:

* **Unisolate Endpoint** — reconnect the endpoint to the network
* **Unlock Device** — unlock the device screen

## Critical Assets and groups

Critical Assets and other endpoint classifications are managed through [Groups](/groups/introduction). The built-in **Critical Asset**, **Domain Controller**, and **Server** groups have remediation disabled by default.

Manual remediation from the case Actions menu remains available. Review how critical assets are represented in your environment before enabling remediation on those groups.

## Supported integrations

Endpoint remediation and release actions are available through connected EDR and MDM integrations, including:

* [Microsoft Defender for Endpoint](/integrations/microsoft)
* [CrowdStrike Falcon](/integrations/crowdstrike-falcon)
* [SentinelOne](/integrations/sentinel-one)
* [Palo Alto Networks Cortex](/integrations/palo-alto-networks-cortex)
* [Sophos](/integrations/sophos)
* [JumpCloud](/integrations/jumpcloud)
* [Kandji](/integrations/kandji)

Each integration supports a subset of the actions above. Isolate is provided by EDR integrations; Lock Device is provided by MDM integrations such as JumpCloud and Kandji. The Remediate or Release dialog only shows actions your connected integration can perform.
