> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# User Remediation

> Automatically remediate compromised users

User remediation automatically (or manually) isolates users when they are associated with malicious detections. If a detection matches a verdict rule with user remediation actions configured, but identity auto-remediation is disabled globally or blocked by group policy, the detection will be escalated to your team.

Remediation is always enabled manually when reviewing a case and selecting Actions > Remediate or Release.

<Info>
  Auto-remediation is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic remediation and escalate the case to your team instead. Manual remediation remains available.
</Info>

## Remediation Actions

Wirespeed can take the following actions to remediate a user:

* **Disable Account** — prevent the user from signing in
* **Reset Password** — force a password change on next sign-in
* **Revoke Sessions** — terminate all active sign-in sessions

Which actions appear in the UI and run for a detection depend on the connected identity provider and the actions selected on the matching verdict rule.

## Release Actions

When a detection is resolved as benign, Wirespeed can automatically reverse user remediation:

* **Enable Account** — re-enable the user account for sign-in

Reset Password and Revoke Sessions are one-shot actions and do not require a separate release step.

## VIPs and NHIs

VIP and NHI users are managed through [Groups](/groups/introduction). The built-in **VIP** and **NHI** groups have remediation disabled by default, so those identities are not automatically remediated even when identity auto-remediation is enabled globally.

Manual remediation from the case Actions menu remains available. Review how VIPs and NHIs are represented in your environment before enabling remediation on those groups.

## Supported integrations

User remediation and release actions are available through connected identity providers, including:

* [Microsoft](/integrations/microsoft)
* [Okta](/integrations/okta)
* [Google Workspace](/integrations/google-workspace)
* [JumpCloud](/integrations/jumpcloud)
* [OneLogin](/integrations/onelogin)
* [Cisco Duo](/integrations/cisco-duo)
* [CyberArk](/integrations/cyberark) (Beta)

Each integration supports a subset of the actions above. The Remediate or Release dialog only shows actions your connected integration can perform.
