---
title: Isolate Hosts & Disable Office365 Accounts With AgileBlue
description: AgileBlue has the ability to isolate hosts and disable user accounts on Office365 via our API integration. There are several ways to initiate this actions, and users can access the Response page to track their containment history.
---

[Skip to content](https://help.agileblue.com/track-responsive-actions-with-agileblue#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en)
3. [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)

# Isolate Hosts & Disable Office365 Accounts With AgileBlue

## AgileBlue has the ability to isolate hosts and disable user accounts on Office365 via our API integration. There are several ways to initiate this actions, and users can access the Response page to track their containment history.

### Overview

By accessing the **Response** page in the left-hand dropdown in the AgileBlue SecOps platform, users can initiate and track host isolation and Office365 account disablement history. On this page, users can track which devices are currently isolated, which Office365 accounts are currently disabled, and audit the history of these responsive actions on each device or user account.

From this page, AgileBlue's expert security team – or your admin users – can also initiate responsive actions, even if the host or user is not tied to an active case.

---

### Isolated Hosts

Under the Isolated Hosts section of the Response page, users will be able to view a list of all devices within their tenant that have been previously isolated or are currently isolated. The current status of each Server or Workstation will be represented by the following icons:

- ![Screenshot 2023-12-01 at 3.24.37 PM](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202023-12-01%20at%203.24.37%20PM.png?width=32&height=24&name=Screenshot%202023-12-01%20at%203.24.37%20PM.png) – Host was previously isolated
- ![Screenshot 2023-12-01 at 3.24.53 PM](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202023-12-01%20at%203.24.53%20PM.png?width=33&height=22&name=Screenshot%202023-12-01%20at%203.24.53%20PM.png) – Host is currently isolated

Selecting the dropdown arrow on the left-hand side of the page will display a full history for the corresponding device including actions performed, the user or analyst who performed the action, the timestamp, and related comments.

Clicking on the red isolated host icon will allow an analyst or user to release the host. Clicking on the white "released" icon will allow the user to re-isolate the host.

Additionally, SOC analysts and admin users can add new hosts for Isolation by clicking the **+** sign in the right-hand corner of the **Isolated Hosts** section. You can also isolate a host by navigating to the **Data Sources** page and selecting the **Workstation** or **Server** icon to the left of the host name.

---

### Disabled Office365 Accounts

Under the Office365 Disabled Users section of the Response page, users will have all of the same capabilities and information provided in the Isolated Hosts section. The current status of each user account will be represented by the following icons:

- ![Screenshot 2023-12-01 at 3.32.24 PM](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202023-12-01%20at%203.32.24%20PM.png?width=25&height=23&name=Screenshot%202023-12-01%20at%203.32.24%20PM.png) – Account was previously disabled
- ![Screenshot 2023-12-01 at 3.32.34 PM](https://help.agileblue.com/hs-fs/hubfs/Screenshot%202023-12-01%20at%203.32.34%20PM.png?width=26&height=25&name=Screenshot%202023-12-01%20at%203.32.34%20PM.png) – Account is currently disabled

Clicking on the red icon will allow an analyst or user to enable the user account. Clicking on the white white icon will allow the user to disable the selected account.

Similar to adding hosts for Isolation, you can also add an Office365 users to be disabled regardless of if they are tied to an active case. To do this, click the **+** sign on the **Office365 Disabled Users** section and type in the full username. Once the user has been added to the list, you can select the **lock** icon shown above to disable or release the user.

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue