To manually isolate a device from the network, you need integration with Kaspersky Endpoint Detection and Response Optimum.
If you manually enable network isolation for a device, you can pre-configure network isolation using the Enabling network isolation (NetworkIsolationStart) local task. You can configure network isolation exclusions and the duration of network isolation for a device.
Enabling network isolation is a predefined task and runs only automatically in the following cases:
You cannot create a new instance of the Enabling network isolation task by clicking the Add button or run the task by clicking the Start button. This task is only available in the device properties, where you can change its settings before enabling network isolation for the device.
The Enabling network isolation task settings apply regardless of whether a policy is applied to the device.
To configure the network isolation parameteres for a device:
The list of managed devices opens.
The list displays only the managed devices for the selected administration group.
The task properties window opens.
The default duration of network isolation is 5 hours.
The minimum duration of network isolation is 1 hour.