You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/air-auto-remediation.md
+17-9Lines changed: 17 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
- m365-security
16
16
- tier2
17
17
description: "Learn about automated remediation in automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2."
18
-
ms.date: 04/02/2025
18
+
ms.date: 04/07/2025
19
19
ms.custom:
20
20
- air
21
21
ms.service: defender-office-365
@@ -35,7 +35,8 @@ By default, remediation actions identified by automated investigation and respon
35
35
36
36
Now, admins can also designate certain actions to automatically remediate. Automatically remediating messages identified as malicious in AIR investigations has the following benefits:
37
37
38
-
- Increases customer protection by expediting neutralizing more threats.
38
+
- Increases customer protection by expediting remediation of more threats.
39
+
39
40
- Saves time for SecOps teams by reducing the need for approval.
40
41
41
42
The rest of this article describes how to configure automated remediation in AIR and how to identify messages that were automatically remediated.
@@ -58,16 +59,19 @@ In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Se
58
59
The following settings are available on the **Automation settings** page:
59
60
60
61
-**Message clusters** section: Specifies the types of message clusters that are automatically remediated. Choose one or more of the following options:
61
-
-**Similar files:** When the automated investigation recognizes a malicious file, it creates a cluster around the malicious file. The cluster groups all messages that contain the file into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious file clusters.
62
-
-**Similar URLs:** When the automated investigation recognizes a malicious URL, it creates a cluster around the malicious URL. The cluster groups all messages that contain the URL into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious URL clusters.
62
+
-**Similar files:** When the automated investigation recognizes a malicious file, it creates a cluster around the malicious file. The cluster groups all messages that contain the file into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious file clusters.
63
+
-**Similar URLs:** When the automated investigation recognizes a malicious URL, it creates a cluster around the malicious URL. The cluster groups all messages that contain the URL into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious URL clusters.
63
64
64
65
> [!TIP]
65
-
> Follow the roadmap to stay informed on when more message clusters are available.
66
+
> Follow the roadmap to stay informed on when more message clusters are available for automated remediation.
66
67
67
68
-**Remediation action** section: Specifies the action to take on message cluster types specified in the **Message clusters** section.
68
69
69
70
Currently, **Soft delete** is the only available action. For more information about soft deleted messages, see [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder).
70
71
72
+
> [!IMPORTANT]
73
+
> The ability to recover soft deleted messages depends on the retention policy for soft deleted messages in each mailbox. Verify your legal obligations for email retention, including messages marked as malicious. For more information on the retention of soft deleted messages, see [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention).
74
+
71
75
When you're finished on the **Automation settings** page, select **Save**.
72
76
73
77
:::image type="content" source="media/auto-air-mdo-automation-settings.png" alt-text="Screenshot of automated remediation of malicious entity clusters configuration in the Defender portal at Settings \> Email & collaboration \> MDO automation settings." lightbox="media/auto-air-mdo-automation-settings.png":::
@@ -94,7 +98,7 @@ For more information about AIR investigation results, see [Details and results o
94
98
95
99
### Automated remediation results in Threat Explorer
96
100
97
-
In Threat Explorer (Explorer), automatically remediated messages have the **Additional action** value **Automated remediation**.
101
+
In Threat Explorer (Explorer), automatically remediated messages have the **Additional action** value **Automated remediation:automated**.
98
102
99
103
For more information about Threat Explorer, see [About Threat Explorer and Real-time detections in Microsoft Defender for Office 365](threat-explorer-real-time-detections-about.md).
100
104
@@ -107,14 +111,18 @@ In Advanced hunting, automatically remediated messages are in the `EmailPostDeli
107
111
-`ActionType` equals **Automated Remediation**
108
112
-`ActionTrigger` equals **Automation**.
109
113
110
-
For more information about Advanced hunting, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](../defender-xdr/advanced-hunting-overview.md).
114
+
For more information about Advanced hunting, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview).
111
115
112
116
:::image type="content" source="media/auto-air-mdo-advanced-hunting.png" alt-text="Screenshot of Advanced hunting for messages removed from mailboxes by automated remediation (EmailPostDeliveryEvents table where the ActionType value is Automated Remediation and the ActionTrigger value is Automation.)" lightbox="media/auto-air-mdo-advanced-hunting.png":::
113
117
114
118
## Revert automated remediation actions on messages
115
119
116
120
> [!NOTE]
117
-
> The ability to recover messages depends on the data still being available and the mailbox retention settings for soft deleted messages. For more information, see [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention).
121
+
> The ability to recover messages depends on the data still being available in Defender and the mailbox retention settings for soft deleted messages. For more information, see the following articles:
122
+
>
123
+
> -[Data retention information for Microsoft Defender for Office 365](/defender-office-365/mdo-data-retention)
124
+
> -[Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder)
125
+
> -[Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention)
118
126
119
127
The following methods are available to revert automated remediation actions and restore messages to mailboxes:
120
128
@@ -126,5 +134,5 @@ The following methods are available to revert automated remediation actions and
126
134
## See also
127
135
128
136
-[AIR in Defender for Office 365 Plan 2](air-about.md)
129
-
-[Review and manage remediation actions in AIR in Defender for Office 365 Plan 2](air-review-approve-pending-completed-actions)
137
+
-[Review and manage remediation actions in AIR in Defender for Office 365 Plan 2](air-review-approve-pending-completed-actions.md)
130
138
-[Remediate malicious email delivered in Office 365](remediate-malicious-email-delivered-office-365.md)
0 commit comments