Take Automated Actions with Action Center
Focus
Focus
Device Security

Take Automated Actions with Action Center

Table of Contents

Take Automated Actions with Action Center

Use Action Center to automate how Device Security responds to events and recurring conditions in your environment.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
Responding to security risks and alerts, and keeping asset metadata updated, can require a lot of manual work that doesn't scale. You click through individual devices to identify a suspicious endpoint, create a policy or switch to a third-party console to run a containment action, then return to Device Security to update tags or notes. As your device count grows into the thousands, this manual approach delays response and pulls analyst time away from investigation.
The Device Security Action Center lets you set up automated actions across Device Security and integrated third-party systems that you want to take when Device Security observes flagged events or behaviors in your network. You configure automations as action sets in Device Security from PoliciesAction Center. The Action Center includes the All Action Sets table, which displays all the action sets in your tenant, along with information about each action set.

Action Center Action Sets

Each action set consists of a trigger, a scope query, and one or more actions, including fallback options.
  • Trigger: Device Security supports three types of trigger. A schedule trigger, an event trigger, and a one-time trigger.
    • Schedule Trigger: A schedule trigger runs on a recurring cadence, which you can configure.
    • Event Trigger: An event trigger runs when Device Security observes a specified event in your environment. Event triggered action sets only evaluate the resource that caused the trigger. For example, if you have an action set configured with a new alert trigger, Device Security only acts on the alert or the device that raised the alert.
      Action sets with event triggers only take effect on event triggers that happen after you create the action set. For example, if you create an action set for an alert event trigger, it doesn't affect past alerts. You need to create a separate one-time action set to act on all existing instances.
      Event triggers can be a new device, new alert, or new vulnerability, or they can be a device attribute change. An event trigger can only monitor a single attribute for change.
      Device Security batches actions for event triggers, so you may see a gap of a few minutes between when an event trigger happens and when the corresponding action happens.
    • One-Time Trigger: A one-time trigger runs when you save the action set.
  • Scope Query: A query that selects the assets the action set runs against. For example, you could select devices located in a specific subnet, or devices that match a specific set of attributes. The scope query supports all entities supported by the query builder. You don't need to define a scope query that matches the event trigger type. For example, you can define a scope with a first level domain of devices, even if the event trigger is a new alert.
  • Main Actions: One or more actions that Device Security takes when the trigger occurs. This can include actions through third-party integrations, such as quarantining an endpoint in CrowdStrike.
  • Fallback Actions: Optional actions that run when any of the main actions fail.
By configuring action sets, you can specify the security concerns relevant to your environment, and then coordinate actions across Device Security and third-party systems from one place. Because the trigger, scope, and action live in the same configuration, you can reuse a scope query across action sets and you can pair a containment action with a tagging action so that responders see the full context the next time they open the device. Fallback actions reduce the operational risk of automation. If your primary endpoint response tool is unavailable, the fallback runs so that the device does not go uncontained.
Each action set is built as an Intent → System → Outcome cascade. You define the intent, such as endpoint containment for devices with internet access that have active alerts for suspicious behavior. The system defines where the action happens, such as selecting a third-party solution like CrowdStrike or Rapid7. The outcome is a result of the action, and reflects the result you want, such as device containment. You can add multiple main actions to a single action set and, optionally, a fallback action that runs if a main action fails. To build your first automation, create an action set.