Quarantine Infected Devices

Efficient quarantine and release procedures are essential for promptly isolating infected devices, minimizing disruptions to the enterprise network.

This streamlined approach enhances endpoint security, swiftly addressing security incidents and reducing the risk of further compromise. A proactive strategy in implementing these measures contributes to a resilient and secure network environment.

Network quarantine

Upon enabling network quarantine for an infected endpoint it will remain isolated from all networks while maintaining a connection only with the Endpoint Central server(all capabilities of Endpoint Central can still be efficiently performed).

Unblocking Network Quarantine

Upon unblocking network quarantine on the device, it will regain full connectivity to all networks. Before proceeding, it is crucial to confirm that all identified threats on the endpoint have been effectively resolved.

To unblock a machine through the console, follow the steps below:

  1. Navigate to Devices in the web console.
  2. Select the computer to be de-isolated from network quarantine and click Unblock.

    Quarantine Unblock

Unblock should occur instantly. If an on-demand connection failure occurs, allow up to 5 hours for the process to complete. If the issue continues after this time, please refer to the manual steps below.

Manual Device Unblocking

If a device remains quarantined, you can manually remove it by following these steps to manually de-isolate it from network quarantine:

  1. Run Command Prompt as an administrator.
  2. Navigate to the EDR agent's bin directory using the command:
    cd C:\Program Files (x86)\ManageEngine\UEMS_Agent\EDR\bin
  3. Execute the de-isolation command:
    EDRDCManager.exe -deisolate
  4. Verify that the device can now access the internet and other network resources.
Was this article helpful?

Thank you for your feedback!

Sorry about that!

By clicking "Submit", you agree to processing of personal data according to thePrivacy Policy.
Back to Top