You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/defender-for-office-365-whats-new.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,6 +39,13 @@ For more information on what's new with other Microsoft Defender security produc
39
39
-[What's new in Microsoft Defender for Identity](/defender-for-identity/whats-new)
40
40
-[What's new in Microsoft Defender for Cloud Apps](/cloud-app-security/release-notes)
41
41
42
+
## May 2024
43
+
44
+
- We are introducing Sender's copy clean-up features in Threat Explorer, email entity, Summary Panel, and Advanced hunting. These new features will streamline the process of managing Sent items, particularly for admins who use Soft delete and Move to inbox actions. For more information, see [Threat Explorer (Explorer)](threat-explorer-real-time-detections-about.md). Key highlights:
45
+
- Integration with Soft delete: Sender's copy clean-up will be incorporated as part of the Soft delete action.
46
+
- Wide support: This action will be supported across various Defender XDR platforms including Threat Explorer, Take Action wizard from the email entity, Summary Panel, Advanced hunting, and through Microsoft Graph API.
47
+
- Undo capability: An undo action will be available, allowing you to reverse the clean-up by moving items back to the Sent folder.
48
+
42
49
## April 2024
43
50
44
51
-**Last used date** added to Tenant Allow/Block List entries for domains and email addresses, files, and URLs.
-**Not actionable**: Emails in the following locations can't be acted on or moved in remediation actions:
89
86
- Quarantine
@@ -96,8 +93,11 @@ Open any remediation item to view details about it, including its remediation na
96
93
-**Move to junk folder**: Moves messages to the user's Junk Email folder.
97
94
-**Move to inbox**: Moves messages to the users Inbox folder.
98
95
-**Move to deleted items**: Moves messages to the user's Deleted Items folder.
99
-
-**Soft delete**: Moves messages to a deleted folder in the cloud.
100
-
-**Hard delete**: Permanently deletes the messages.
96
+
-**Soft delete**: Delete the message from the Deleted items folder (move to the Recoverable Items\Deletions folder). The message is recoverable by the user and admins.
97
+
98
+
**Delete sender's copy**: Also try to soft delete the message from the sender's Sent Items folder if the sender is the organization.
99
+
100
+
-**Hard delete**: Purge the deleted message. Admins can recover hard deleted items using single-item recovery. For more information about hard deleted and soft deleted items, see [Soft-deleted and hard-deleted items](/compliance/assurance/assurance-exchange-online-data-deletion#soft-deleted-and-hard-deleted-items).
101
101
102
102
Suspicious messages are categorized as either remediable or nonremediable. In most cases, remediable and nonremediable messages combine equals total messages submitted. But in rare cases this may not be true. This can happen because of system delays, timeouts, or expired messages. Messages expire based on the Explorer retention period for your organization.
For more information about what Microsoft does to your submissions, [check this out](submissions-report-messages-files-to-microsoft.md#report-suspicious-email-messages-to-microsoft).
30
+
For more information about how Microsoft stores and handle your submissions, [check this out](submissions-report-messages-files-to-microsoft.md#report-suspicious-email-messages-to-microsoft).
31
31
32
32
In Microsoft 365 organizations with Exchange Online mailboxes, admins can use the **Submissions** page in the Microsoft Defender portal to submit messages, URLs, and attachments to Microsoft for analysis. There are two basic types of admin submissions:
33
33
@@ -39,7 +39,7 @@ In Microsoft 365 organizations with Exchange Online mailboxes, admins can use th
39
39
40
40
After an admin submits the message from the **User reported** tab, an entry is also created on the corresponding tab on the **Submissions** page (for example, the **Emails** tab). These types of admin submissions are described in the [Admin options for user reported messages](#admin-options-for-user-reported-messages) section.
41
41
42
-
When admins submit messages to Microsoft for analysis, we do the following checks:
42
+
When admins submit messages or sends user report to Microsoft for analysis, we do the following checks:
43
43
44
44
-**Email authentication check** (email messages only): Whether email authentication passed or failed when it was delivered.
45
45
-**Policy hits**: Information about any policies or overrides that might have allowed or blocked the incoming email into the organization, thus overriding our filtering verdicts.
Copy file name to clipboardExpand all lines: defender-office-365/threat-explorer-threat-hunting.md
+10-6Lines changed: 10 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ author: chrisda
7
7
manager: deniseb
8
8
audience: ITPro
9
9
ms.topic: conceptual
10
-
ms.date: 4/26/2024
10
+
ms.date: 05/20/2024
11
11
ms.localizationpriority: medium
12
12
ms.collection:
13
13
- m365-security
@@ -176,15 +176,13 @@ Selecting :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" b
176
176
|---|:---:|:---:|
177
177
|**Move to mailbox folder**|✔¹||
178
178
|**Submit to Microsoft for review**|✔|✔|
179
-
| **Allow or block entries in the Tenant Allow/Block List**³|✔|✔|
179
+
| **Allow or block entries in the Tenant Allow/Block List**²|✔|✔|
180
180
|**Initiate automated investigation**|✔||
181
-
|**Propose remediation**|✔|²|
181
+
|**Propose remediation**|✔||
182
182
183
183
¹ This action requires the **Search and Purge** role in [Email & collaboration permissions](mdo-portal-permissions.md). By default, this role is assigned only to the **Data Investigator** and **Organization Management** role groups. You can add users to those role groups, or you can [create a new role group](mdo-portal-permissions.md#create-email--collaboration-role-groups-in-the-microsoft-defender-portal) with the **Search and Purge** role assigned, and add the users to the custom role group.
184
184
185
-
² Although this action might appear available in Real-time detections, it's not available in Defender for Office 365 Plan 1.
186
-
187
-
³ This action is available under **Submit to Microsoft for review**.
185
+
² This action is available under **Submit to Microsoft for review**.
188
186
189
187
The **Take action** wizard is described in the following list:
190
188
@@ -205,8 +203,14 @@ The **Take action** wizard is described in the following list:
205
203
-**Move to mailbox folder**: Select one of the available values that appear:
206
204
-**Junk**: Move the message to the Junk Email folder.
207
205
-**Inbox**: Move the message to the Inbox.
206
+
207
+
**Move back to Sent Items folder**: Also try to move the message from the sender's Recoverable Items\Deletions folder to the Sent Items folder if the sender is the organization.
208
+
208
209
-**Deleted items**: Move the message to the Deleted items folder.
209
210
-**Soft deleted items**: Delete the message from the Deleted items folder (move to the Recoverable Items\Deletions folder). The message is recoverable by the user and admins.
211
+
212
+
**Delete sender's copy**: Also try to soft delete the message from the sender's Sent Items folder if the sender is the organization.
213
+
210
214
-**Hard deleted items**: Purge the deleted message. Admins can recover hard deleted items using single-item recovery. For more information about hard deleted and soft deleted items, see [Soft-deleted and hard-deleted items](/compliance/assurance/assurance-exchange-online-data-deletion#soft-deleted-and-hard-deleted-items).
211
215
212
216
-**Submit to Microsoft for review**: Select one of the available values that appear:
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-take-action.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -80,6 +80,8 @@ Apart from device-focused remediation steps, you can also take some actions on e
80
80
81
81
-`Delete email` - select this to move email messages to the Deleted items folder (**Soft delete**) or delete them permanently (**Hard delete**)
82
82
83
+
Selecting **Soft delete** also offers the option to **Delete sender's copy**, which also tries to soft delete the message from the sender's Sent Items folder if the sender is the organization.
84
+
83
85
:::image type="content" source="/defender/media/advanced-hunting-take-actions-email-del.png" alt-text="The Take actions option in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-take-actions-email-del.png":::
84
86
85
87
You can also provide a remediation name and a short description of the action taken to easily track it in the action center history. You can also use the Approval ID to filter for these actions in the action center. This ID is provided at the end of the wizard:
0 commit comments