Qualys EDR-Quarantine Host Configuration List Support

Limited Customer Release Notes

Version 3.8.1

January 18, 2026

What is Quarantine Host Configuration List Support?

The Quarantine Host Configuration List Support enables managing multiple quarantine configuration profiles in a list format rather than applying a single quarantine profile manually. Previously, only one default profile was available for quarantine configurations. This enhancement offers flexibility and consistency when isolating hosts suspected of compromise, thereby preventing threats from spreading across the network and maintaining continuous monitoring of the host.

Benefits

The integration of Quarantine Host Configuration List Support with Qualys EDR provides several benefits:

  • Create and maintain a list of quarantine profiles for different scenarios.
  • Ensures faster response by applying the correct profile immediately with continuous monitoring without losing visibility of the host.
  • Operational efficiency by saving time and reducing complexity during incidents.

How Quarantine Host Configuration List Support Works in Qualys EDR

When integrating with Qualys EDR, the system allows to choose a configuration profile from the multiple configuration profiles listed to quarantine the assets.

The assets can be quarantined from the Incidents, Alerts, or Assets tabs.

Quarantine an Asset from the Assets Tab

To quarantine an asset from the Assets tab, perform the following steps:

  1. Hover the mouse over the asset that is quarantined to view the Quick Actions menu.
  2. Click Quarantine Asset.

  3. In the Quarantine Asset window, add comments, if any.
  4. Select a profile configuration from the Apply Saved Profile(s) drop-down list. The configurations of the selected profile will be loaded on the asset.
  5. Allow specific domains, applications, or IP addresses to access a quarantined asset, if any.
  6. Click Quarantine Asset.



    A notification Quarantine Asset Request sent successfully. View Request Status is generated.

  7. Click View Request Status to view the asset quarantine status.

    A quarantined asset displays the  icon.
Quarantine an Asset from the Incidents Tab

To quarantine an asset from the Incidents tab, perform the following steps:

  1. Hover the mouse over an Incident Description to view the Quick Actions menu. 
  2. Click the Incident Details that you want to quarantine.
  3. In the Summary section, click Quarantine Asset.

  4. In the Quarantine Asset window, add comments, if any, similar to the Assets tab from step 3.
  5. Select a profile configuration from the Apply Saved Profile(s) drop-down list.
  6. Allow specific domains, applications, or IP addresses to access a quarantined asset, if any.
  7. Click Quarantine Asset.



    A notification Quarantine Asset Request sent successfully. View Request Status is generated.

  8. Click View Request Status to view the asset quarantine status.

    A quarantined asset displays the  icon.

Similarly, you can follow the same steps to quarantine an asset from the Alerts tab.

What Roles are supported in Quarantine Host Configuration List Support?

The Quarantine Host Configuration List Support supports tags-based user roles for profile management, each with specific permissions to create, edit, and manage profiles. 

The user roles behavior is as follows:

  • Admin user: The Admin cannot create a profile and can only edit a profile created by the managers.
  • Auditor user: The Auditor has the same roles as the Admin user. They can edit the profiles created by their assigned managers only. 
  • Manager user: The managers can create and edit their own profiles.
  • Sub user: The end users can only access profiles created by their managers within the same scope. 

What QQL Tokens are Supported?

You can use the following search token for the Asset Configuration page:

Token Description
name

Use this token to search a profile based on the name of the profile.

Example, 

To show all the profiles having this profile name.

name:default