Microsoft Graph · Schema

defenderThreatAction

Defender’s default action to take on detected Malware threats.

Azure ADCollaborationContactsDocumentsEmailGraphIdentityMicrosoftOffice 365PresentationsProductivitySpreadsheetsT1Tasks
View JSON Schema on GitHub

JSON Schema

microsoft-graph-microsoftgraphdefenderthreataction-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "#/components/schemas/microsoft.graph.defenderThreatAction",
  "title": "defenderThreatAction",
  "enum": [
    "deviceDefault",
    "clean",
    "quarantine",
    "remove",
    "allow",
    "userDefined",
    "block"
  ],
  "type": "string",
  "description": "Defender\u2019s default action to take on detected Malware threats.",
  "x-ms-enum": {
    "name": "defenderThreatAction",
    "modelAsString": false,
    "values": [
      {
        "value": "deviceDefault",
        "description": "Apply action based on the update definition.",
        "name": "deviceDefault"
      },
      {
        "value": "clean",
        "description": "Clean the detected threat.",
        "name": "clean"
      },
      {
        "value": "quarantine",
        "description": "Quarantine the detected threat.",
        "name": "quarantine"
      },
      {
        "value": "remove",
        "description": "Remove the detected threat.",
        "name": "remove"
      },
      {
        "value": "allow",
        "description": "Allow the detected threat.",
        "name": "allow"
      },
      {
        "value": "userDefined",
        "description": "Allow the user to determine the action to take with the detected threat.",
        "name": "userDefined"
      },
      {
        "value": "block",
        "description": "Block the detected threat.",
        "name": "block"
      }
    ]
  }
}