Response Actions
Understand the response actions that appear in your cases.
When you execute a response action during incident response, such as disabling a compromised user account or isolating an infected endpoint, it's essential to understand what that action does, which systems it affects, and whether it can safely be reversed.
This comprehensive reference guide documents all available response actions across your integrated security platforms, including their required parameters, API endpoints, impact levels, and - most importantly - their undo capabilities. Many actions can be automatically reversed with a single click, giving you full control to contain threats confidently and restore normal operations when incidents are resolved. Use this guide to make informed decisions during incident response and understand the full scope of each remediation action.
Prerequisites
Find your action connector
CrowdStrike Actions
CrowdStrike action connectors use the CrowdStrike Falcon API to perform endpoint detection and response (EDR) actions. These actions are commonly used for endpoint containment, threat intelligence, and indicator management during incident response. CrowdStrike Falcon provides cloud-native endpoint protection with real-time threat intelligence.
Primary use cases: Endpoint containment, custom IOC management, threat blocking
Google Workspace Actions
Google Workspace action connectors use the Google Workspace Admin SDK and Gmail API to perform email security and user management actions. These actions are commonly used for email threat remediation and sender blocking during incident response. Google Workspace provides cloud-based productivity and collaboration tools with integrated security controls.
Primary use cases: Phishing email removal, malicious sender blocking
KnowBe4 Actions
KnowBe4 action connectors use the KnowBe4 Reporting API to perform security awareness training actions. These actions are commonly used for phishing training enrollment and user education during and after security incidents. KnowBe4 provides security awareness training and simulated phishing campaigns.
Primary use cases: Post-incident training, phishing awareness education
Microsoft 365 Actions
Microsoft 365 action connectors use Microsoft Graph API, Microsoft Defender for Endpoint API, and Exchange Online API to perform response actions across endpoints, email, identity, and security controls. These actions are commonly used for containment, remediation, and account protection during incident response. The connector integrates with multiple Microsoft security services including Azure AD, Exchange Online, and Microsoft Defender.
Primary use cases: Account compromise response, email security, endpoint containment, malware blocking
Mimecast Actions
Mimecast action connectors use the Mimecast API V2 to perform email security and threat protection actions. These actions are commonly used for email sender blocking, URL blocking, and threat containment during incident response. Mimecast provides cloud-based email security, archiving, and continuity services.
Primary use cases: Phishing sender blocking, malicious URL blocking, domain-based threat prevention
Netskope Actions
Netskope action connectors use the Netskope REST API v2 to perform cloud access security broker (CASB) and secure web gateway (SWG) actions. These actions are commonly used for URL blocking and web content filtering during incident response. Netskope provides cloud-native security for SaaS, IaaS, and web traffic.
Primary use cases: Malicious URL blocking, web threat containment
Okta Actions
Okta action connectors use the Okta Management API to perform identity and access management operations. These actions are commonly used for account security, session management, and network access control during incident response. Okta serves as a centralized identity provider for managing user authentication and authorization.
Primary use cases: User account lockdown, session termination, IP-based access control
Proofpoint Actions
Proofpoint action connectors use the Proofpoint API to perform email security and threat protection actions. These actions are commonly used for email sender blocking and spam prevention during incident response. Proofpoint provides advanced email security, threat intelligence, and compliance solutions.
Primary use cases: Malicious sender blocking, phishing prevention
SentinelOne Actions
SentinelOne action connectors use the SentinelOne Management Console API to perform endpoint protection and response actions. These actions are commonly used for endpoint containment, threat remediation, and malware blocking during incident response. SentinelOne provides autonomous endpoint protection with AI-driven threat detection.
Primary use cases: Endpoint isolation, malware scanning, file hash blocking
Zscaler OneAPI Actions
Zscaler OneAPI action connectors use the Zscaler OneAPI framework to perform secure web gateway (SWG) actions against Zscaler Internet Access (ZIA). These actions are commonly used for malicious URL containment during phishing response. Zscaler provides cloud-based web security and zero-trust network access.
Primary use cases: Malicious URL blocking, phishing URL remediation
Revert Capabilities
Understand revert capabilities
Revert capability determines if an action can be automatically reversed through the platform. Actions with revert support have a paired reversal action. For example, isolate_device can be undone with release_device, and disable_user can be reversed with enable_user. This gives you confidence to act decisively, knowing you can quickly restore normal operations.
How to reverse an action
If you need to undo a remediation step (for example, re-enabling a user after an investigation clears them), you can often do so directly from the same view.
Go to the table where you ran the action and find the affected artifact.
Click to open the right side drawer menu.
Look for the undo button in the Action history section.
Confirm to revert the action.

Some actions are inherently irreversible due to their nature or vendor API limitations. The Actions without revert support table lists why certain actions cannot be automatically reversed. For irreversible actions, we recommend extra caution and choosing less destructive alternatives when possible (e.g., soft delete instead of hard delete an email).
Actions with revert support
disable_users_and_
terminate_active_sessions
enable_user
Okta, MS365
enable_user
disable_users_and_
terminate_active_sessions
Okta, MS365
isolate_device
release_device
MS365 Defender, SentinelOne, CrowdStrike
release_device
isolate_device
MS365 Defender, SentinelOne, CrowdStrike
block_ip
unblock_ip
Okta
unblock_ip
block_ip
Okta
find_and_soft_delete_emails
restore_soft_deleted_emails
MS365
restore_soft_deleted_emails
find_and_soft_delete_emails
MS365
block_file
unblock_file
MS365
Defender
unblock_file
block_file
MS365
Defender
block_url
unblock_url
Zscaler
unblock_url
block_url
Zscaler
Actions without revert support
terminate_active_sessions
Sessions already terminated
Okta, MS365
reset_user_password
Password already changed
Okta, MS365
disable_all_forward_rules
Manual re-enablement required
MS365
delete_external_forward_rules
Rules permanently deleted
MS365
find_and_hard_delete_emails
Permanent deletion
MS365, Google Workspace
block_domain
Manual removal required
MS365 Defender
block_file
Vendor API does not support unblocking
SentinelOne, CrowdStrike
run_full_disk_scan
Scan already initiated
SentinelOne
block_url
Manual removal from URL list/managed URLs required
Netskope, Mimecast
block_url_domain
Manual removal from managed URLs required
Mimecast
block_sender
Manual removal from sender list/filters required
Proofpoint, Google Workspace, Mimecast
block_sender_domain
Manual removal from group required
Mimecast
block_ip
Manual policy removal required
MS365
enroll_in_phishing_training
Training enrollment cannot be undone
KnowBe4
Impact Level Definitions
High: Significant operational impact; requires immediate attention to restore.
Medium: Moderate operational impact; users can work around limitation.
Low: Minimal operational impact, easily reversible or limited to enrichment only.
Last updated
Was this helpful?