You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/air-about.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -67,7 +67,7 @@ An alert is triggered, and a security playbook starts an automated investigation
67
67
During and after each automated investigation, the SecOps team can do the following tasks:
68
68
69
69
-[View details about an alert related to an investigation](air-view-investigation-results.md#view-details-about-an-alert-related-to-an-investigation)
70
-
-[View the results details of an investigation](air-view-investigation-results.md#view-investigation-details-in-the-defender-portal-from-air-in-defender-for-office-365)
70
+
-[View the results details of an investigation](air-view-investigation-results.md#view-investigation-details-from-air-in-defender-for-office-365-plan-2)
71
71
-[Review and approve actions as a result of an investigation](air-review-approve-pending-completed-actions.md)
72
72
73
73
## Required permissions and licensing for AIR
@@ -96,6 +96,6 @@ AIR contains data for users with Defender for Office 365 licenses assigned to th
96
96
## Next steps
97
97
98
98
-[AIR examples](air-examples.md)
99
-
-[See details and results of an automated investigation](air-view-investigation-results.md#view-investigation-details-in-the-defender-portal-from-air-in-defender-for-office-365)
99
+
-[See details and results of an automated investigation](air-view-investigation-results.md#view-investigation-details-from-air-in-defender-for-office-365-plan-2)
100
100
-[Review and approve pending actions](air-remediation-actions.md)
101
101
-[View pending or completed remediation actions](air-review-approve-pending-completed-actions.md)
Copy file name to clipboardExpand all lines: defender-office-365/air-view-investigation-results.md
+31-30Lines changed: 31 additions & 30 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -42,7 +42,7 @@ By default, investigation details from yesterday and today are shown, but you ca
42
42
43
43
The following information shown on the **Investigations** page. You can sort the entries by clicking on an available column header. Select :::image type="icon" source="media/m365-cc-sc-customize-icon.png" border="false"::: **Customize columns** to change the columns that are shown. By default, all available columns are selected:
44
44
45
-
-**ID**: The unique ID of the investigation. Select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** to open the details of the investigation as described in the [View investigation details](#view-investigation-details-from-air-in-defender-for-office-365) section.
45
+
-**ID**: The unique ID of the investigation. Select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** to open the details of the investigation as described in the [View investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) section.
46
46
-**Status**: The available status values are described in the [Investigation Status values](#investigation-status-values) section.
47
47
-**Detection Source**: This value is always **Office365**.
48
48
-**Investigation**
@@ -91,7 +91,7 @@ The **Status** values that are used in investigations are described in the follo
91
91
92
92
-**Failed**: At least one investigation analyzer ran into a problem where it couldn't complete properly.
93
93
94
-
If an investigation fails after remediation actions were approved, the remediation actions might still have succeeded. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365).
94
+
If an investigation fails after remediation actions were approved, the remediation actions might still have succeeded. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2).
95
95
96
96
-**No Threats Found**: The investigation finished and no threats were identified (compromised user accounts, email messages, URLs, or files).
97
97
@@ -112,15 +112,15 @@ The **Status** values that are used in investigations are described in the follo
112
112
113
113
-**Pending Action**: The investigation found a threat (for example, a malicious email, a malicious URL, or a risky mailbox setting), and an action to remediate the threat is [awaiting approval](air-review-approve-pending-completed-actions.md).
114
114
115
-
The list of pending actions can increase as an investigation runs. [View the investigation details](#view-investigation-details-from-air-in-defender-for-office-365) to see if other items are still pending completion.
115
+
The list of pending actions can increase as an investigation runs. [View the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) to see if other items are still pending completion.
116
116
117
117
-**Queued By Throttling**: An investigation is being held in a queue. When other investigations complete, queued investigations begin. Throttling helps avoid poor service performance.
118
118
119
119
Pending actions can limit how many new investigations can run. Make sure to [approve or reject pending actions](air-review-approve-pending-completed-actions.md#approve-or-reject-pending-actions-from-the-investigations-page-in-defender-for-office-365).
120
120
121
121
-**Remediated**: The investigation finished and all remediation actions were approved (noted as fully remediated).
122
122
123
-
Approved remediation actions can have errors that prevent the actions from being taken. Regardless of whether remediation actions are successfully completed, the investigation status doesn't change. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365).
123
+
Approved remediation actions can have errors that prevent the actions from being taken. Regardless of whether remediation actions are successfully completed, the investigation status doesn't change. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2).
124
124
125
125
-**Running**: The investigation process is underway. This status value also occurs when [pending actions](air-review-approve-pending-completed-actions.md#approve-or-reject-pending-actions-from-the-investigations-page-in-defender-for-office-365) are approved.
126
126
@@ -136,7 +136,7 @@ The **Status** values that are used in investigations are described in the follo
136
136
137
137
You can [start an investigation from Threat Explorer (Explorer)](air-examples.md#example-a-security-administrator-triggers-an-investigation-from-threat-explorer).
138
138
139
-
## View investigation details from AIR in Defender for Office 365
139
+
## View investigation details from AIR in Defender for Office 365 Plan 2
140
140
141
141
When you select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** in the **ID** column of an entry on the **Investigations** page at <https://security.microsoft.com/airinvestigation>, a new page opens with the investigation details.
142
142
@@ -258,30 +258,31 @@ Clicking anywhere else in the row other than the check box next to the first col
258
258
#### Manage alert
259
259
260
260
:::image type="icon" source="media/m365-cc-sc-edit-icon.png" border="false"::: **Manage alert**: Opens a **Manage alert** flyout where you can view and modify details about the incident. You can modify the following alert properties:
261
-
- **Status**: Select one of the following values:
262
-
- **New**
263
-
- **In progress**
264
-
- **Resolved**
265
-
- **Classification**: Select one of the following values:
266
-
- **Not set**
267
-
- **True positive** section:
268
-
- **Multi staged attack**
269
-
- **Malware**
270
-
- **Malicious user activity**
271
-
- **Unwanted software**
272
-
- **Phishing**
273
-
- **Compromised account**
274
-
- **Other**
275
-
- **Informational, expected activity** section:
276
-
- **Security testing**
277
-
- **Confirmed activity**
278
-
- **Line of business application**
279
-
- **Other**
280
-
- **False positive** section:
281
-
- **Not malicious**
282
-
- **Not enough data to validate**
283
-
- **Other**
284
-
- **Comment**: Enter an optional comment.
261
+
262
+
-**Status**: Select one of the following values:
263
+
-**New**
264
+
-**In progress**
265
+
-**Resolved**
266
+
-**Classification**: Select one of the following values:
267
+
-**Not set**
268
+
-**True positive** section:
269
+
-**Multi staged attack**
270
+
-**Malware**
271
+
-**Malicious user activity**
272
+
-**Unwanted software**
273
+
-**Phishing**
274
+
-**Compromised account**
275
+
-**Other**
276
+
-**Informational, expected activity** section:
277
+
-**Security testing**
278
+
-**Confirmed activity**
279
+
-**Line of business application**
280
+
-**Other**
281
+
-**False positive** section:
282
+
-**Not malicious**
283
+
-**Not enough data to validate**
284
+
-**Other**
285
+
-**Comment**: Enter an optional comment.
285
286
286
287
When you're finished in the **Manage alert** flyout, select **Save**
287
288
@@ -576,7 +577,7 @@ Certain kinds of alerts trigger automated investigation in Microsoft 365. To lea
576
577
1. On the **Action center** page, use the **Pending** or **History** tabs to find the action.
577
578
1. Select an action from the table by selecting the link in the **Investigation ID** column.
578
579
579
-
The [investigation details page](#view-investigation-details-from-air-in-defender-for-office-365) opens.
580
+
The [investigation details page](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) opens.
0 commit comments