Skip to content

Commit 16a9e50

Browse files
authored
Merge pull request #3392 from KCrider14/docs-editor/air-auto-remediation-1743964834
Update air-auto-remediation.md
2 parents 651270a + a33f3e5 commit 16a9e50

File tree

1 file changed

+17
-9
lines changed

1 file changed

+17
-9
lines changed

defender-office-365/air-auto-remediation.md

Lines changed: 17 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
- m365-security
1616
- tier2
1717
description: "Learn about automated remediation in automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2."
18-
ms.date: 04/02/2025
18+
ms.date: 04/07/2025
1919
ms.custom:
2020
- air
2121
ms.service: defender-office-365
@@ -35,7 +35,8 @@ By default, remediation actions identified by automated investigation and respon
3535

3636
Now, admins can also designate certain actions to automatically remediate. Automatically remediating messages identified as malicious in AIR investigations has the following benefits:
3737

38-
- Increases customer protection by expediting neutralizing more threats.
38+
- Increases customer protection by expediting remediation of more threats.
39+
3940
- Saves time for SecOps teams by reducing the need for approval.
4041

4142
The rest of this article describes how to configure automated remediation in AIR and how to identify messages that were automatically remediated.
@@ -58,16 +59,19 @@ In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Se
5859
The following settings are available on the **Automation settings** page:
5960

6061
- **Message clusters** section: Specifies the types of message clusters that are automatically remediated. Choose one or more of the following options:
61-
- **Similar files:** When the automated investigation recognizes a malicious file, it creates a cluster around the malicious file. The cluster groups all messages that contain the file into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious file clusters.
62-
- **Similar URLs:** When the automated investigation recognizes a malicious URL, it creates a cluster around the malicious URL. The cluster groups all messages that contain the URL into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious URL clusters.
62+
- **Similar files:** When the automated investigation recognizes a malicious file, it creates a cluster around the malicious file. The cluster groups all messages that contain the file into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious file clusters.
63+
- **Similar URLs:** When the automated investigation recognizes a malicious URL, it creates a cluster around the malicious URL. The cluster groups all messages that contain the URL into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious URL clusters.
6364

6465
> [!TIP]
65-
> Follow the roadmap to stay informed on when more message clusters are available.
66+
> Follow the roadmap to stay informed on when more message clusters are available for automated remediation.
6667
6768
- **Remediation action** section: Specifies the action to take on message cluster types specified in the **Message clusters** section.
6869

6970
Currently, **Soft delete** is the only available action. For more information about soft deleted messages, see [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder).
7071

72+
> [!IMPORTANT]
73+
> The ability to recover soft deleted messages depends on the retention policy for soft deleted messages in each mailbox. Verify your legal obligations for email retention, including messages marked as malicious. For more information on the retention of soft deleted messages, see [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention).
74+
7175
When you're finished on the **Automation settings** page, select **Save**.
7276

7377
:::image type="content" source="media/auto-air-mdo-automation-settings.png" alt-text="Screenshot of automated remediation of malicious entity clusters configuration in the Defender portal at Settings \> Email & collaboration \> MDO automation settings." lightbox="media/auto-air-mdo-automation-settings.png":::
@@ -94,7 +98,7 @@ For more information about AIR investigation results, see [Details and results o
9498

9599
### Automated remediation results in Threat Explorer
96100

97-
In Threat Explorer (Explorer), automatically remediated messages have the **Additional action** value **Automated remediation**.
101+
In Threat Explorer (Explorer), automatically remediated messages have the **Additional action** value **Automated remediation:automated**.
98102

99103
For more information about Threat Explorer, see [About Threat Explorer and Real-time detections in Microsoft Defender for Office 365](threat-explorer-real-time-detections-about.md).
100104

@@ -107,14 +111,18 @@ In Advanced hunting, automatically remediated messages are in the `EmailPostDeli
107111
- `ActionType` equals **Automated Remediation**
108112
- `ActionTrigger` equals **Automation**.
109113

110-
For more information about Advanced hunting, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](../defender-xdr/advanced-hunting-overview.md).
114+
For more information about Advanced hunting, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview).
111115

112116
:::image type="content" source="media/auto-air-mdo-advanced-hunting.png" alt-text="Screenshot of Advanced hunting for messages removed from mailboxes by automated remediation (EmailPostDeliveryEvents table where the ActionType value is Automated Remediation and the ActionTrigger value is Automation.)" lightbox="media/auto-air-mdo-advanced-hunting.png":::
113117

114118
## Revert automated remediation actions on messages
115119

116120
> [!NOTE]
117-
> The ability to recover messages depends on the data still being available and the mailbox retention settings for soft deleted messages. For more information, see [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention).
121+
> The ability to recover messages depends on the data still being available in Defender and the mailbox retention settings for soft deleted messages. For more information, see the following articles:
122+
>
123+
> - [Data retention information for Microsoft Defender for Office 365](/defender-office-365/mdo-data-retention)
124+
> - [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder)
125+
> - [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention)
118126
119127
The following methods are available to revert automated remediation actions and restore messages to mailboxes:
120128

@@ -126,5 +134,5 @@ The following methods are available to revert automated remediation actions and
126134
## See also
127135

128136
- [AIR in Defender for Office 365 Plan 2](air-about.md)
129-
- [Review and manage remediation actions in AIR in Defender for Office 365 Plan 2](air-review-approve-pending-completed-actions)
137+
- [Review and manage remediation actions in AIR in Defender for Office 365 Plan 2](air-review-approve-pending-completed-actions.md)
130138
- [Remediate malicious email delivered in Office 365](remediate-malicious-email-delivered-office-365.md)

0 commit comments

Comments
 (0)