Skip to content

Commit 381015a

Browse files
authored
Merge pull request #2408 from MicrosoftDocs/AIR-chrisda
AIR-chrisda to Main
2 parents 79a77a8 + e0df707 commit 381015a

File tree

39 files changed

+832
-309
lines changed

39 files changed

+832
-309
lines changed

defender-office-365/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -444,7 +444,7 @@
444444
items:
445445
- name: AIR overview
446446
href: air-about.md
447-
- name: How automated investigation and response works
447+
- name: AIR examples
448448
href: air-examples.md
449449
- name: Review and approve (or reject) pending actions
450450
href: air-review-approve-pending-completed-actions.md

defender-office-365/address-compromised-users-quickly.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ When a user account is compromised, alerts are triggered. And in some cases, tha
4747
- [View details about automated investigations](#view-details-about-automated-investigations)
4848

4949
> [!IMPORTANT]
50-
> You must have appropriate permissions to perform the following tasks. See [Required permissions to use AIR capabilities](air-about.md#required-permissions-to-use-air-capabilities).
50+
> You must have appropriate permissions to perform the following tasks. For more information, see [Required permissions to use AIR capabilities](air-about.md#required-permissions-and-licensing-for-air).
5151
5252
Watch this short video to learn how you can detect and respond to user compromise in Microsoft Defender for Office 365 using Automated Investigation and Response (AIR) and compromised user alerts.
5353

@@ -81,7 +81,7 @@ To learn more, see [View details of an investigation](air-view-investigation-res
8181

8282
## Next steps
8383

84-
- [Review the required permissions to use AIR capabilities](air-about.md#required-permissions-to-use-air-capabilities)
84+
- [Review the required permissions to use AIR capabilities](air-about.md#required-permissions-and-licensing-for-air)
8585

8686
- [Find and investigate malicious email in Office 365](threat-explorer-investigate-delivered-malicious-email.md)
8787

defender-office-365/air-about.md

Lines changed: 40 additions & 68 deletions
Large diffs are not rendered by default.

defender-office-365/air-custom-reporting.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
11
---
22
title: Custom reporting solutions with automated investigation and response
3-
f1.keywords:
3+
f1.keywords:
44
- NOCSH
55
author: chrisda
66
ms.author: chrisda
77
manager: deniseb
88
audience: ITPro
99
ms.topic: conceptual
1010
ms.localizationpriority: medium
11-
search.appverid:
11+
search.appverid:
1212
- MET150
1313
- MOE150
14-
ms.collection:
14+
ms.collection:
1515
- m365-security
1616
- tier2
1717
description: Learn how to integrate automated investigation and response with a custom or third-party reporting solution.
18-
ms.date: 06/09/2023
18+
ms.date: 07/10/2024
1919
ms.custom:
2020
- air
2121
ms.service: defender-office-365
@@ -24,11 +24,13 @@ appliesto:
2424
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
2525
---
2626

27-
# Custom or third-party reporting solutions for Microsoft Defender for Office 365
27+
# Custom or third-party reporting solutions for Microsoft Defender for Office 365 Plan 2
2828

2929
[!INCLUDE [MDO Trial banner](../includes/mdo-trial-banner.md)]
3030

31-
With [Microsoft Defender for Office 365](mdo-about.md), you get [detailed information about automated investigations](air-view-investigation-results.md). However, some organizations also use a custom or third-party reporting solution. If your organization wants to integrate information about [automated investigations](air-about.md) with such a solution, you can use the Office 365 Management Activity API.
31+
Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2 returns detailed information about the results. For more information, see [Details and results of automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2](air-view-investigation-results.md).
32+
33+
However, some Microsoft 365 organizations use custom or third-party reporting solutions. Those organizations can use the **Office 365 Management Activity APIs** to integrate information from AIR into other reporting solutions.
3234

3335
|Resource|Description|
3436
|:---|:---|

defender-office-365/air-examples.md

Lines changed: 44 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: How automated investigation and response works in Microsoft Defender for Office 365
2+
title: Automated investigation and response examples
33
f1.keywords:
44
- NOCSH
55
author: chrisda
@@ -14,8 +14,8 @@ search.appverid:
1414
ms.collection:
1515
- m365-security
1616
- tier2
17-
ms.date: 06/09/2023
18-
description: See how automated investigation and response capabilities work in Microsoft Defender for Office 365
17+
ms.date: 01/10/2025
18+
description: See examples for how to start automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2.
1919
ms.custom:
2020
- air
2121
- seo-marvel-mar2020
@@ -25,67 +25,72 @@ appliesto:
2525
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
2626
---
2727

28-
# How automated investigation and response works in Microsoft Defender for Office 365
28+
# Automated investigation and response (AIR) examples in Microsoft Defender for Office 365 Plan 2
2929

3030
[!INCLUDE [MDO Trial banner](../includes/mdo-trial-banner.md)]
3131

32-
As security alerts are triggered, it's up to your security operations team to look into those alerts and take steps to protect your organization. Sometimes, security operations teams can feel overwhelmed by the volume of alerts that are triggered. Automated investigation and response (AIR) capabilities in Microsoft Defender for Office 365 can help.
32+
Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2 (included in Microsoft 365 licenses like E5 or as a standalone subscription) enables your SecOps team to operate more efficiently and effectively. AIR includes automated investigations to well-known threats, and provides recommended remediation actions. The SecOps team can review the evidence and approve or reject the recommended actions. For more information about AIR, see [Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2](air-about.md).
3333

34-
AIR enables your security operations team to operate more efficiently and effectively. AIR capabilities include automated investigation processes in response to well-known threats that exist today. Appropriate remediation actions await approval, enabling your security operations team to respond to detected threats.
34+
This article describes how AIR works through several examples:
3535

36-
This article describes how AIR works through several examples. When you're ready to get started using AIR, see [Automatically investigate and respond to threats](air-about.md).
36+
- [Example: A user-reported phishing message launches an investigation playbook](#example-a-user-reported-phishing-message-launches-an-investigation-playbook)
37+
- [Example: A security administrator triggers an investigation from Threat Explorer](#example-a-security-administrator-triggers-an-investigation-from-threat-explorer)
38+
- [Example: A security operations team integrates AIR with their SIEM using the Office 365 Management Activity API](#example-a-security-operations-team-integrates-air-with-their-siem-using-the-office-365-management-activity-api)
3739

38-
- [Example 1: A user-reported phish message launches an investigation playbook](#example-a-user-reported-phish-message-launches-an-investigation-playbook)
39-
- [Example 2: A security administrator triggers an investigation from Threat Explorer](#example-a-security-administrator-triggers-an-investigation-from-threat-explorer)
40-
- [Example 3: A security operations team integrates AIR with their SIEM using the Office 365 Management Activity API](#example-a-security-operations-team-integrates-air-with-their-siem-using-the-office-365-management-activity-api)
40+
## Example: A user-reported phishing message launches an investigation playbook
4141

42-
## Example: A user-reported phish message launches an investigation playbook
42+
A user receives an email that looks like a phishing attempt. The user reports the message using the [Microsoft Report Message or Report Phishing add-ins](submissions-users-report-message-add-in-configure.md), which results in an alert that's triggered by the **Email reported by user as malware or phish** [alert policy](/purview/alert-policies#threat-management-alert-policies), which automatically launches the investigation playbook.
4343

44-
Suppose that a user in your organization receives an email that they think is a phishing attempt. The user, trained to report such messages, uses the [Microsoft Report Message or Report Phishing add-ins](submissions-users-report-message-add-in-configure.md) to send it to Microsoft for analysis. The submission is also sent to your system and is visible in Explorer in the **Submissions** view (formerly referred to as the **User-reported** view). In addition, the user-reported message now triggers a system-based informational alert, which automatically launches the investigation playbook.
44+
Various aspects of the reported email message are assessed. For example:
4545

46-
During the root investigation phase, various aspects of the email are assessed. These aspects include:
46+
- The identified threat type
47+
- Who sent the message
48+
- Where the message was sent from (sending infrastructure)
49+
- Whether other instances of the message were delivered or blocked
50+
- The tenant landscape, including similar messages and their verdicts through email clustering
51+
- Whether the message is associated with any known campaigns
52+
- And more.
4753

48-
- A determination about what type of threat it might be;
49-
- Who sent it;
50-
- Where the email was sent from (sending infrastructure);
51-
- Whether other instances of the email were delivered or blocked;
52-
- An assessment from our analysts;
53-
- Whether the email is associated with any known campaigns;
54-
- and more.
54+
The playbook evaluates and automatically resolves submissions where no action is needed (which frequently happens on user reported messages). For the remaining submissions, a list of recommended actions to take on the original message and the associated _entities_ (for example, attached files, included URLs, and recipients) is provided:
5555

56-
After the root investigation is complete, the playbook provides a list of recommended actions to take on the original email and the _entities_ associated with it (for example, files, URLs, and recipients).
56+
- Identify similar email messages via email cluster searches.
57+
- Determine whether any users clicked through any malicious links in suspicious email messages.
58+
- Risks and threats are assigned. For more information, see [Details and results of an automated investigation](air-view-investigation-results.md).
59+
- Remediation steps. For more information, see [Remediation actions in Microsoft Defender for Office 365](air-remediation-actions.md).
5760

58-
Next, several threat investigation and hunting steps are executed:
61+
## Example: A security administrator triggers an investigation from Threat Explorer
5962

60-
- Similar email messages are identified via email cluster searches.
61-
- The signal is shared with other platforms, such as [Microsoft Defender for Endpoint](/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection).
62-
- A determination is made on whether any users have clicked through any malicious links in suspicious email messages.
63-
- A check is done across [Exchange Online Protection](eop-about.md) (EOP) and [Microsoft Defender for Office 365](mdo-about.md) to see if there are any other similar messages reported by users.
64-
- A check is done to see if a user has been compromised. This check leverages signals across Office 365, [Microsoft Defender for Cloud Apps](/cloud-app-security), and [Microsoft Entra ID](/azure/active-directory), correlating any related user activity anomalies.
63+
You're in Explorer (Threat Explorer) at <https://security.microsoft.com/threatexplorerv3> in the **All email**, **Malware**, or **Phish** views. You're on the **Email** tab (view) of the details area below the chart. You select a message to investigate by using either of the following methods:
6564

66-
During the hunting phase, risks and threats are assigned to various hunting steps.
65+
- Select one or more entries in the table by selecting the check box next to the first column. :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** is available directly in the tab.
6766

68-
Remediation is the final phase of the playbook. During this phase, remediation steps are taken, based on the investigation and hunting phases.
67+
:::image type="content" source="media/te-rtd-all-email-view-take-action.png" alt-text="Screenshot of the Email view (tab) of the details table with a message selected and Take action active." lightbox="media/te-rtd-all-email-view-take-action.png":::
6968

70-
## Example: A security administrator triggers an investigation from Threat Explorer
69+
- Click on the **Subject** value of an entry in the table. The details flyout that opens contains :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout.
7170

72-
In addition to automated investigations that are triggered by an alert, your organization's security operations team can trigger an automated investigation from a view in [Threat Explorer](threat-explorer-real-time-detections-about.md). This investigation also creates an alert, so Microsoft Defender XDR incidents and external SIEM tools can see that this investigation was triggered.
71+
:::image type="content" source="media/te-rtd-all-email-view-email-tab-details-area-subject-details-flyout-actions-only.png" alt-text="The actions available in the details tab after you select a Subject value in the Email tab of the details area in the All email view." lightbox="media/te-rtd-all-email-view-email-tab-details-area-subject-details-flyout-actions-only.png":::
7372

74-
For example, suppose that you are using the **Malware** view in Explorer. Using the tabs below the chart, you select the **Email** tab. If you select one or more items in the list, the **+ Actions** button activates.
73+
After you select :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action**, select **Initiate automated investigation**. For more information, see [Email remediation](threat-explorer-threat-hunting.md#email-remediation).
7574

76-
:::image type="content" source="media/Explorer-Malware-Email-ActionsInvestigate.png" alt-text="The Explorer with selected messages" lightbox="media/Explorer-Malware-Email-ActionsInvestigate.png":::
75+
Similar to playbooks triggered by an alert, automatic investigations that are triggered from Threat Explorer include:
7776

78-
Using the **Actions** menu, you can select **Trigger investigation**.
77+
- A root investigation.
78+
- Steps to identify and correlate threats. For more information, see [Details and results of an automated investigation](air-view-investigation-results.md).
79+
- Recommended actions to mitigate threats. For more information, see [Remediation actions in Microsoft Defender for Office 365](air-remediation-actions.md).
7980

80-
:::image type="content" source="media/explorer-malwareview-selectedemails-actions.jpg" alt-text="The Actions menu for selected messages" lightbox="media/explorer-malwareview-selectedemails-actions.jpg":::
81+
## Example: A security operations team integrates AIR with their SIEM using the Office 365 Management Activity API
8182

82-
Similar to playbooks triggered by an alert, automatic investigations that are triggered from a view in Explorer include a root investigation, steps to identify and correlate threats, and recommended actions to mitigate those threats.
83+
AIR capabilities in Defender for Office 365 Plan 2 include [reports and details](air-view-investigation-results.md) that the SecOps team can use to monitor and address threats. But you can also integrate AIR capabilities with other solutions. For example:
8384

84-
## Example: A security operations team integrates AIR with their SIEM using the Office 365 Management Activity API
85+
- Security information and event management (SIEM) systems.
86+
- Case management systems.
87+
- Custom reporting solutions.
88+
89+
Use the [Office 365 Management Activity API](/office/office-365-management-api/office-365-management-activity-api-reference) for integration with these solutions.
8590

86-
AIR capabilities in Microsoft Defender for Office 365 include [reports & details](air-view-investigation-results.md) that security operations teams can use to monitor and address threats. But you can also integrate AIR capabilities with other solutions. Examples include a security information and event management (SIEM) system, a case management system, or a custom reporting solution. These kinds of integrations can be done by using the [Office 365 Management Activity API](/office/office-365-management-api/office-365-management-activity-api-reference).
91+
For an example of a custom solution that integrates alerts from user-reported phishing messages that were already processed by AIR into a SIEM server and case management system, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the Office 365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).
8792

88-
For example, recently, an organization set up a way for their security operations team to view user-reported phish alerts that were already processed by AIR. Their solution integrates relevant alerts with the organization's SIEM server and their case-management system. The solution greatly reduces the number of false positives so that their security operations team can focus their time and effort on real threats. To learn more about this custom solution, see [Tech Community blog: Improve the Effectiveness of your SOC with Microsoft Defender for Office 365 and the O365 Management API](https://techcommunity.microsoft.com/t5/microsoft-security-and/improve-the-effectiveness-of-your-soc-with-office-365-atp-and/ba-p/1525185).
93+
The integrated solution greatly reduces the number of false positives, which allows the SecOps team to focus their time and effort on real threats.
8994

9095
## Next steps
9196

0 commit comments

Comments
 (0)