Skip to main content
User remediation automatically (or manually) isolates users when they are associated with malicious detections. If a detection matches a verdict rule with user remediation actions configured, but identity auto-remediation is disabled globally or blocked by group policy, the detection will be escalated to your team. Remediation is always enabled manually when reviewing a case and selecting Actions > Remediate or Release.
Auto-remediation is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic remediation and escalate the case to your team instead. Manual remediation remains available.

Remediation Actions

Wirespeed can take the following actions to remediate a user:
  • Disable Account — prevent the user from signing in
  • Require MFA Re-enrollment — remove registered MFA methods so the user must enroll again at the next sign-in that requires strong authentication
  • Reset Password — force a password change on next sign-in
  • Revoke Sessions — terminate all active sign-in sessions
For Microsoft Entra accounts synced from on-premises Active Directory, Wirespeed cannot reset the password through Microsoft Graph and skips that action. Microsoft Graph can report a successful account disable, but a later directory sync can re-enable the account because on-premises Active Directory remains authoritative. Wirespeed continues other configured remediation such as revoking sessions. During automatic remediation, the skipped password reset escalates the detection for analyst follow-up. Reset the password and disable the account in on-premises Active Directory to make those actions durable.
Which actions appear in the UI and run for a detection depend on the connected identity provider and the actions selected on the matching verdict rule.

Release Actions

When a detection is resolved as benign, Wirespeed can automatically reverse user remediation:
  • Enable Account — re-enable the user account for sign-in
Require MFA Re-enrollment, Reset Password, and Revoke Sessions are one-shot actions and do not require a separate release step. Require MFA Re-enrollment is destructive: removed authentication methods cannot be restored by Wirespeed, and the user must register new methods before satisfying an MFA challenge.

VIPs and NHIs

VIP and NHI users are managed through Groups. The built-in VIP and NHI groups have remediation disabled by default, so those identities are not automatically remediated even when identity auto-remediation is enabled globally. Manual remediation from the case Actions menu remains available. Review how VIPs and NHIs are represented in your environment before enabling remediation on those groups.

Supported integrations

User remediation and release actions are available through connected identity providers, including: Each integration supports a subset of the actions above. The Remediate or Release dialog only shows actions your connected integration can perform.